Ibm Qradar Siem vulnerabilities

101 known vulnerabilities affecting ibm/qradar_siem.

Total CVEs
101
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH33MEDIUM58LOW6

Vulnerabilities

Page 1 of 6
CVE-2026-1276MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2026-1276 [MEDIUM] CWE-79 CVE-2026-1276: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vu IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-15051MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2025-15051 [MEDIUM] CWE-79 CVE-2025-15051: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vu IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality.
cvelistv5nvd
CVE-2025-36051MEDIUMCVSS 5.5≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2025-36051 [MEDIUM] CWE-538 CVE-2025-36051: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in co IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
cvelistv5nvd
CVE-2025-36007HIGHCVSS 7.8≥ 7.5.0, ≤ 7.5.0 UP13 IF022025-10-27
CVE-2025-36007 [HIGH] CWE-266 CVE-2025-36007: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escal IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.
cvelistv5nvd
CVE-2025-36138MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 132025-10-27
CVE-2025-36138 [MEDIUM] CWE-79 CVE-2025-36138: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-si IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-36170MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 132025-10-27
CVE-2025-36170 [MEDIUM] CWE-79 CVE-2025-36170: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-si IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-0164LOWCVSS 2.3≥ 7.5, ≤ 7.5.0 UP13 IF012025-09-14
CVE-2025-0164 [LOW] CWE-732 CVE-2025-0164: IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged use IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
cvelistv5nvd
CVE-2025-33120HIGHCVSS 7.8≥ 7.5, ≤ 7.5.0 Update Pack 132025-08-22
CVE-2025-33120 [HIGH] CWE-250 CVE-2025-33120: IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privilege IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.
cvelistv5nvd
CVE-2025-36042MEDIUMCVSS 5.4≥ 7.5, ≤ 7.5.0 Update Pack 132025-08-22
CVE-2025-36042 [MEDIUM] CWE-79 CVE-2025-36042: IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerabilit IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-33118MEDIUMCVSS 5.4≥ 7.5, ≤ 7.5.0 Update Pack 122025-08-01
CVE-2025-33118 [MEDIUM] CWE-79 CVE-2025-33118: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-33097MEDIUMCVSS 5.4≥ 7.5,, ≤ 7.5.0 Update Pack 122025-07-15
CVE-2025-33097 [MEDIUM] CWE-79 CVE-2025-33097: IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerabili IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-33117CRITICALCVSS 9.1≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-33117 [CRITICAL] CWE-73 CVE-2025-33117: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configu IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.
cvelistv5nvd
CVE-2025-33121HIGHCVSS 7.1≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-33121 [HIGH] CWE-611 CVE-2025-33121: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injecti IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
cvelistv5nvd
CVE-2025-36050MEDIUMCVSS 6.2≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-36050 [MEDIUM] CWE-532 CVE-2025-36050: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
cvelistv5nvd
CVE-2024-56463MEDIUMCVSS 4.8≥ 7.5, ≤ 7.5.0 UP112025-02-14
CVE-2024-56463 [MEDIUM] CWE-79 CVE-2024-56463: IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged us IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-28786MEDIUMCVSS 6.5v7.52025-01-28
CVE-2024-28786 [MEDIUM] CWE-319 CVE-2024-28786: IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication ch IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
cvelistv5nvd
CVE-2024-47107MEDIUMCVSS 5.4v7.52024-12-07
CVE-2024-47107 [MEDIUM] CWE-79 CVE-2024-47107: IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenti IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-27269MEDIUMCVSS 6.8v7.52024-05-14
CVE-2024-27269 [MEDIUM] CWE-286 CVE-2024-27269: IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose u IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.
cvelistv5nvd
CVE-2023-50949HIGHCVSS 8.1v7.52024-04-11
CVE-2023-50949 [MEDIUM] CWE-295 CVE-2023-50949: IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.
cvelistv5nvd
CVE-2024-28784MEDIUMCVSS 5.4v7.52024-03-27
CVE-2024-28784 [MEDIUM] CWE-79 CVE-2024-28784: IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.
cvelistv5nvd