cbcvebase.

Ibm Qradar Siem vulnerabilities

99 known vulnerabilities affecting ibm/qradar_siem.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH33MEDIUM56LOW6

Vulnerabilities

Page 3 of 5
CVE-2023-47146P4MEDIUMCVSS 6.5v7.52023-12-19
CVE-2023-47146 [MEDIUM] CWE-200 CVE-2023-47146: IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.
nvd
CVE-2022-34352P4MEDIUMCVSS 6.5v7.52023-06-27
CVE-2022-34352 [MEDIUM] CWE-200 CVE-2022-34352: IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.
nvd
CVE-2020-4151P4MEDIUMCVSS 6.5v7.3.0v7.3.32020-04-14
CVE-2020-4151 [MEDIUM] CWE-20 CVE-2020-4151: IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized ac IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-Force ID: 174201.
nvd
CVE-2021-29880P4MEDIUMCVSS 6.5v7.4.32021-08-13
CVE-2021-29880 [MEDIUM] CVE-2021-29880: IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
nvd
CVE-2020-4883P4MEDIUMCVSS 6.5v7.3v7.42021-05-05
CVE-2020-4883 [MEDIUM] CVE-2020-4883: IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X-Force ID: 190907.
nvd
CVE-2024-27269P4MEDIUMCVSS 6.8v7.52024-05-14
CVE-2024-27269 [MEDIUM] CWE-286 CVE-2024-27269: IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose u IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.
nvd
CVE-2021-29779P4MEDIUMCVSS 5.9v7.3v7.42021-12-01
CVE-2021-29779 [MEDIUM] CVE-2021-29779: IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the serve IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
nvd
CVE-2020-4511P4MEDIUMCVSS 6.5v7.3v7.42020-07-14
CVE-2020-4511 [MEDIUM] CVE-2020-4511: IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qf IBM QRadar SIEM 7.3 and 7.4 could allow an authenticated user to cause a denial of service of the qflow process by sending a malformed sflow command. IBM X-Force ID: 182366.
nvd
CVE-2024-28786P4MEDIUMCVSS 6.5v7.52025-01-28
CVE-2024-28786 [MEDIUM] CWE-319 CVE-2024-28786: IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication ch IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
nvd
CVE-2019-4264P4MEDIUMCVSS 5.9v7.2.82019-05-29
CVE-2019-4264 [MEDIUM] CWE-295 CVE-2019-4264: IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
nvd
CVE-2019-4262P4MEDIUMCVSS 5.3v7.2v7.32019-09-26
CVE-2019-4262 [MEDIUM] CWE-918 CVE-2019-4262: IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an u IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.
nvd
CVE-2018-1733P4MEDIUMCVSS 5.3v7.2v7.32019-01-29
CVE-2018-1733 [MEDIUM] CVE-2018-1733: IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that ha IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.
nvd
CVE-2018-1650P4MEDIUMCVSS 5.5v7.2v7.32018-12-05
CVE-2018-1650 [MEDIUM] CWE-798 CVE-2018-1650: IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
nvd
CVE-2025-36138P4MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 132025-10-27
CVE-2025-36138 [MEDIUM] CWE-79 CVE-2025-36138: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-si IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36170P4MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 132025-10-27
CVE-2025-36170 [MEDIUM] CWE-79 CVE-2025-36170: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-si IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2026-1276P4MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2026-1276 [MEDIUM] CWE-79 CVE-2026-1276: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vu IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-20392P4MEDIUMCVSS 6.1v1.0.0v4.1.12021-05-14
CVE-2021-20392 [MEDIUM] CWE-79 CVE-2021-20392: IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This v IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-20397P4MEDIUMCVSS 6.1v7.3v7.42021-05-05
CVE-2021-20397 [MEDIUM] CWE-79 CVE-2021-20397: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196017.
nvd
CVE-2021-29849P4MEDIUMCVSS 6.1v7.3v7.42021-12-01
CVE-2021-29849 [MEDIUM] CWE-79 CVE-2021-29849: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281.
nvd
CVE-2025-36050P4MEDIUMCVSS 6.2≥ 7.5, ≤ 7.5.0 Update Pack 122025-06-19
CVE-2025-36050 [MEDIUM] CWE-532 CVE-2025-36050: IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.
nvd
Ibm Qradar Siem vulnerabilities | cvebase