← back
CVE-2020-4294

CVE-2020-4294

CVSS 6.3 MEDIUMEPSS 1.2%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 Apr 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.
CVSS:3.0/UI:N/AV:N/PR:L/AC:L/C:L/I:L/S:U/A:L/RC:C/E:U/RL:O
Affected products
IBM · Qradar

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →