Incorrect Regular Expression in UAParser.js - CVE-2020-7793
Published: May 26, 2022 / Updated: May 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
SINEC INS
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2020-7793
SINEC INS - update to 1.0 SP2
IBM Security QRadar Analyst Workflow - update to 2.15.1