Vulnerability record · CVE-2020-4888 · published 28 January 2021
CVE-2020-4888: IBM QRadar SIEM Java deserialization allows remote command execution
Ibm · Qradar Security Information And Event Manager
IBM QRadar SIEM versions 7.4.0 through 7.4.2 Patch 1 and 7.3.0 through 7.3.3 Patch 7 deserialize user-supplied content insecurely, allowing a remote attacker to execute arbitrary commands via a malicious serialized Java object. Because QRadar is a central security monitoring platform, compromise can undermine the very visibility defenders rely on.
Description
IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 190912.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with full confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires authenticated low-privileged access and no KEV listing exists.
What it is
IBM QRadar SIEM versions 7.4.0 through 7.4.2 Patch 1 and 7.3.0 through 7.3.3 Patch 7 deserialize user-supplied content insecurely, allowing a remote attacker to execute arbitrary commands via a malicious serialized Java object. Because QRadar is a central security monitoring platform, compromise can undermine the very visibility defenders rely on.
Impact
An attacker with a valid low-privileged account can execute arbitrary commands on the QRadar system, gaining full control over confidentiality, integrity and availability of that host.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires the attacker to hold low-level privileges (PR:L), meaning some form of authenticated access to the application is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.61964, 99.1st percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the IBM fix referenced in support page node/6409306 for the affected 7.3.x and 7.4.x builds.
- Restrict network access to QRadar management and console interfaces to trusted administrative networks.
- Enforce least privilege and review accounts with low-privileged access to the QRadar application.
- Monitor and alert on unexpected Java deserialization activity or unusual child processes spawned by QRadar services.
Detection
- Monitor QRadar application logs and host process telemetry for unexpected command execution or shell spawning from Java processes.
- Alert on anomalous outbound connections from QRadar hosts that could indicate post-exploitation activity.
- Audit authentication logs for use of low-privileged accounts against deserialization-exposed endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/190912 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6409306 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/190912 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6409306 | PatchVendor Advisory |
Track CVE-2020-4888 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.