CVE-2020-4408

MEDIUM

IBM QRadar Advisor 1.1-2.5.2 - Insufficiently Protected Credentials via Password Masking

Title source: llm
STIX 2.1

Description

The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6252401
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/179536

Scores

CVSS v3 4.6
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (1)
ibm/qradar_advisory 1.1 - 2.5.2
Published Jul 27, 2020
Tracked Since Feb 18, 2026