Lucene search

K
ibmIBM97A176E78EC8C5DE0F387E4307F253F702CEBE34D99D5F851133362E788CC9F6
HistoryDec 15, 2020 - 5:05 p.m.

Security Bulletin: PostgresSQL JDBC Driver as used in IBM QRadar SIEM is vulnerable to information disclosure (CVE-2020-13692)

2020-12-1517:05:50
www.ibm.com
129

0.017 Low

EPSS

Percentile

87.7%

Summary

PostgresSQL JDBC Driver as used in IBM QRadar SIEM is vulnerable to information disclosure caused by an XML external entity (XXE)

Vulnerability Details

CVEID:CVE-2020-13692
**DESCRIPTION:**PostgreSQL JDBC Driver could allow a remote authenticated attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data. By sending specially crafted XML data, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/183018 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM QRadar 7.3.0 to 7.3.3 Patch 5

IBM QRadar 7.4.0 to 7.4.1 Patch 1

Remediation/Fixes

QRadar / QRM / QVM / QRIF / QNI 7.3.3 Patch 6
QRadar / QRM / QVM / QRIF / QNI 7.4.1 Patch 2
QRadar / QRM / QVM / QRIF / QNI 7.4.2 GA

Workarounds and Mitigations

None