cbcvebase.

Ibm Qradar Siem vulnerabilities

99 known vulnerabilities affecting ibm/qradar_siem.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH33MEDIUM56LOW6

Vulnerabilities

Page 1 of 5
CVE-2020-4280P2HIGHCVSS 8.8v7.3.0v7.3.3.Patch.4+2 more2020-10-08
CVE-2020-4280 [HIGH] CWE-502 CVE-2020-4280: IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the syste IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 1
nvd
CVE-2018-1612P2MEDIUMCVSS 5.8PoCv7.2v7.32018-07-17
CVE-2018-1612 [MEDIUM] CWE-200 CVE-2018-1612: IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164.
nvd
CVE-2020-4888P2HIGHCVSS 8.8v7.3v7.4+2 more2021-01-28
CVE-2020-4888 [HIGH] CWE-502 CVE-2020-4888: IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to e IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker could exploit this vulnerability to execute arbitrary com
nvd
CVE-2018-1571P2HIGHCVSS 8.8v7.2v7.32018-09-11
CVE-2018-1571 [HIGH] CVE-2018-1571: IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 143121.
nvd
CVE-2020-4979P3CRITICALCVSS 9.8v7.3v7.42021-05-05
CVE-2020-4979 [CRITICAL] CVE-2020-4979: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker th IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
nvd
CVE-2025-33117P3CRITICALCVSS 9.1≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-33117 [CRITICAL] CWE-73 CVE-2025-33117: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configu IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.
nvd
CVE-2021-20399P3CRITICALCVSS 9.1v7.3.0v7.4.0+2 more2021-07-27
CVE-2021-20399 [CRITICAL] CWE-611 CVE-2021-20399: IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
nvd
CVE-2020-5013P3HIGHCVSS 8.1v7.3v7.42021-05-05
CVE-2020-5013 [HIGH] CWE-611 CVE-2020-5013: IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when proc IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 193245.
nvd
CVE-2019-4210P3HIGHCVSS 8.1v7.3.22019-04-08
CVE-2019-4210 [HIGH] CVE-2019-4210: IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality whi IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.
nvd
CVE-2020-4512P3HIGHCVSS 7.2v7.3v7.42020-07-14
CVE-2020-4512 [HIGH] CWE-78 CVE-2020-4512: IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands. IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.
nvd
CVE-2021-38869P3CRITICALCVSS 9.8v7.3.3v7.4.3+1 more2022-04-27
CVE-2021-38869 [CRITICAL] CWE-384 CVE-2021-38869: IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
nvd
CVE-2025-33120P3HIGHCVSS 7.8≥ 7.5, ≤ 7.5.0 Update Pack 132025-08-22
CVE-2025-33120 [HIGH] CWE-250 CVE-2025-33120: IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privilege IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.
nvd
CVE-2025-36007P3HIGHCVSS 7.8≥ 7.5.0, ≤ 7.5.0 UP13 IF022025-10-27
CVE-2025-36007 [HIGH] CWE-266 CVE-2025-36007: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escal IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.
nvd
CVE-2023-50949P3HIGHCVSS 8.1v7.52024-04-11
CVE-2023-50949 [HIGH] CWE-295 CVE-2023-50949: IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.
nvd
CVE-2020-4509P3HIGHCVSS 7.6v7.3v7.42020-06-04
CVE-2020-4509 [HIGH] CWE-611 CVE-2020-4509: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when proc IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364.
nvd
CVE-2018-1730P3HIGHCVSS 7.1v7.2v7.32018-12-05
CVE-2018-1730 [HIGH] CWE-611 CVE-2018-1730: IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when proce IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147709.
nvd
CVE-2025-33121P3HIGHCVSS 7.1≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-33121 [HIGH] CWE-611 CVE-2025-33121: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injecti IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2019-4545P3HIGHCVSS 7.5v7.3.0v7.3.3.Patch.4+2 more2020-10-08
CVE-2019-4545 [HIGH] CVE-2019-4545: IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptibl IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
nvd
CVE-2020-4789P3MEDIUMCVSS 6.5v7.3.0v7.4.0+4 more2021-01-27
CVE-2020-4789 [MEDIUM] CWE-22 CVE-2020-4789: IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 189302.
nvd
CVE-2021-38878P3HIGHCVSS 7.5v7.3.3v7.4.3+1 more2022-04-27
CVE-2021-38878 [HIGH] CVE-2021-38878: IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchan IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
nvd
Ibm Qradar Siem vulnerabilities | cvebase