CVE-2020-5013
published 2021-05-05CVE-2020-5013: IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
1.47%
70.8th percentile
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | >= 7.3.0 < 7.3.3 | 7.3.3 |
| ibm | qradar_security_information_and_event_manager | >= 7.4.0 < 7.4.2 | 7.4.2 |
| ibm | qradar_siem | — | — |
| ibm | qradar_siem | — | — |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm1 | 229-4ubuntu21.31+esm1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h827-x5f6-x45j: IBM QRadar SIEM 7
ghsa_unreviewed·2022-05-24
CVE-2020-5013 [HIGH] CWE-611 GHSA-h827-x5f6-x45j: IBM QRadar SIEM 7
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.
OSV
systemd vulnerabilities
osv·2021-07-20·CVSS 6.1
CVE-2021-33910 systemd vulnerabilities
systemd vulnerabilities
USN-5013-1 fixed several vulnerabilities in systemd. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-05
Published