CVE-2020-4271
published 2020-04-15CVE-2020-4271: IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM…
PriorityP337medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
1.73%
75.0th percentile
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| ibm | qradar | — | — |
| ibm | qradar | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | >= 7.3.0 < 7.3.3 | 7.3.3 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6m87-rx2w-j7jv: IBM QRadar 7
ghsa_unreviewed·2022-05-24
CVE-2020-4271 [MEDIUM] CWE-502 GHSA-6m87-rx2w-j7jv: IBM QRadar 7
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.
Apache
Apache nifi: CVE-2020-9487
vendor_apache·CVSS 7.5
CVE-2020-9487 Apache nifi: CVE-2020-9487
Apache nifi: CVE-2020-9487
Title: Potential Denial of Service with Token Authentication Requests Published: 2020-08-18 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Dennis Detering, IT Security Consultant at Spike Reply References CVE Record: CVE-2020-9487 NVD Record: CVE-2020-9487 Apache Jira Issue: NIFI-7385 GitHub Pull Request: 4271 The NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly request download tokens, preventing legitimate users from requesting download tokens. NiFi 1.12.0 disabled anonymous authentication, implemented a multi-index
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/157336/QRadar-Community-Edition-7.3.1.6-PHP-Object-Injection.htmlhttp://seclists.org/fulldisclosure/2020/Apr/39https://exchange.xforce.ibmcloud.com/vulnerabilities/175897https://www.ibm.com/support/pages/node/6189651http://packetstormsecurity.com/files/157336/QRadar-Community-Edition-7.3.1.6-PHP-Object-Injection.htmlhttp://seclists.org/fulldisclosure/2020/Apr/39https://exchange.xforce.ibmcloud.com/vulnerabilities/175897https://www.ibm.com/support/pages/node/6189651
2020-04-15
Published