cbcvebase.

Ibm Qradar Siem vulnerabilities

99 known vulnerabilities affecting ibm/qradar_siem.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH33MEDIUM56LOW6

Vulnerabilities

Page 4 of 5
CVE-2018-1729P4MEDIUMCVSS 5.3v7.32019-04-19
CVE-2018-1729 [MEDIUM] CWE-200 CVE-2018-1729: IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be us IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147708.
nvd
CVE-2021-20429P4MEDIUMCVSS 5.3v1.0.0v4.1.12021-05-14
CVE-2021-20429 [MEDIUM] CWE-863 CVE-2021-20429: IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an o IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334.
nvd
CVE-2021-38939P4MEDIUMCVSS 5.3v7.3.3v7.4.3+1 more2022-04-27
CVE-2021-38939 [MEDIUM] CWE-532 CVE-2021-38939: IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could b IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.
nvd
CVE-2025-36051P4MEDIUMCVSS 5.5≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2025-36051 [MEDIUM] CWE-538 CVE-2025-36051: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in co IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
nvd
CVE-2025-33118P4MEDIUMCVSS 5.4≥ 7.5, ≤ 7.5.0 Update Pack 122025-08-01
CVE-2025-33118 [MEDIUM] CWE-79 CVE-2025-33118: IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-36042P4MEDIUMCVSS 5.4≥ 7.5, ≤ 7.5.0 Update Pack 132025-08-22
CVE-2025-36042 [MEDIUM] CWE-79 CVE-2025-36042: IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerabilit IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-50950P4MEDIUMCVSS 5.3v7.52024-01-17
CVE-2023-50950 [MEDIUM] CWE-200 CVE-2023-50950: IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.
nvd
CVE-2020-4993P4MEDIUMCVSS 4.9v7.3v7.42021-05-05
CVE-2020-4993 [MEDIUM] CWE-22 CVE-2020-4993: IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.
nvd
CVE-2018-2021P4MEDIUMCVSS 6.1v7.2v7.32019-07-17
CVE-2018-2021 [MEDIUM] CWE-79 CVE-2018-2021: IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.
nvd
CVE-2020-4513P4MEDIUMCVSS 6.1v7.3v7.42020-07-14
CVE-2020-4513 [MEDIUM] CWE-79 CVE-2020-4513: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182368.
nvd
CVE-2018-2022P4MEDIUMCVSS 5.3v7.2v7.32019-07-17
CVE-2018-2022 [MEDIUM] CWE-200 CVE-2018-2022: IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information c IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.
nvd
CVE-2020-4929P4MEDIUMCVSS 5.4v7.3v7.42021-05-05
CVE-2020-4929 [MEDIUM] CWE-79 CVE-2020-4929: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191706.
nvd
CVE-2024-28784P4MEDIUMCVSS 5.4v7.52024-03-27
CVE-2024-28784 [MEDIUM] CWE-79 CVE-2024-28784: IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.
nvd
CVE-2023-50961P4MEDIUMCVSS 5.4v7.52024-03-27
CVE-2023-50961 [MEDIUM] CWE-79 CVE-2023-50961: IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275939.
nvd
CVE-2023-40367P4MEDIUMCVSS 5.4v7.5.02023-10-14
CVE-2023-40367 [MEDIUM] CWE-79 CVE-2023-40367: IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 263376.
nvd
CVE-2024-47107P4MEDIUMCVSS 5.4v7.52024-12-07
CVE-2024-47107 [MEDIUM] CWE-79 CVE-2024-47107: IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenti IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-33097P4MEDIUMCVSS 5.4≥ 7.5,, ≤ 7.5.0 Update Pack 122025-07-15
CVE-2025-33097 [MEDIUM] CWE-79 CVE-2025-33097: IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerabili IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2025-15051P4MEDIUMCVSS 5.4≥ 7.5.0, ≤ 7.5.0 Update Pack 142026-03-19
CVE-2025-15051 [MEDIUM] CWE-79 CVE-2025-15051: IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vu IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality.
nvd
CVE-2019-4559P4MEDIUMCVSS 5.3v7.3.0v7.3.32020-01-10
CVE-2019-4559 [MEDIUM] CWE-200 CVE-2019-4559: IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The infor IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
nvd
CVE-2019-4211P4MEDIUMCVSS 5.4v7.2v7.32019-07-17
CVE-2019-4211 [MEDIUM] CWE-79 CVE-2019-4211: IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.
nvd