cbcvebase.

Ibm Qradar Siem vulnerabilities

99 known vulnerabilities affecting ibm/qradar_siem.

Total CVEs
99
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH33MEDIUM56LOW6

Vulnerabilities

Page 5 of 5
CVE-2018-1728P4MEDIUMCVSS 5.4v7.2v7.32018-12-05
CVE-2018-1728 [MEDIUM] CWE-79 CVE-2018-1728: IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707.
nvd
CVE-2020-4364P4MEDIUMCVSS 5.4v7.3v7.42020-07-14
CVE-2020-4364 [MEDIUM] CWE-79 CVE-2020-4364: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178961.
nvd
CVE-2021-38936P4MEDIUMCVSS 4.9v7.3.0v7.4.0+4 more2022-07-20
CVE-2021-38936 [MEDIUM] CVE-2021-38936: IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.
nvd
CVE-2021-39041P4MEDIUMCVSS 5.3v7.3v7.4+1 more2022-07-12
CVE-2021-39041 [MEDIUM] CVE-2021-39041: IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting i IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports. IBM X-Force ID: 214028.
nvd
CVE-2022-22424P4MEDIUMCVSS 5.5v7.3.0v7.4.0+4 more2022-07-20
CVE-2022-22424 [MEDIUM] CWE-276 CVE-2022-22424: IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
nvd
CVE-2022-22345P4MEDIUMCVSS 4.8v7.3.3v7.4.3+1 more2022-04-27
CVE-2022-22345 [MEDIUM] CWE-79 CVE-2022-22345: IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.
nvd
CVE-2020-4786P4MEDIUMCVSS 4.3v7.3v7.42021-01-27
CVE-2020-4786 [MEDIUM] CWE-918 CVE-2020-4786: IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vul IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189221.
nvd
CVE-2022-30613P4MEDIUMCVSS 5.5v7.4.0v7.5.02022-10-07
CVE-2022-30613 [MEDIUM] CVE-2022-30613: IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.
nvd
CVE-2022-22320P4MEDIUMCVSS 4.8v7.3v7.42022-05-11
CVE-2022-22320 [MEDIUM] CWE-79 CVE-2022-22320: IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users t IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.
nvd
CVE-2024-56463P4MEDIUMCVSS 4.8≥ 7.5, ≤ 7.5.0 UP112025-02-14
CVE-2024-56463 [MEDIUM] CWE-79 CVE-2024-56463: IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged us IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-38874P4MEDIUMCVSS 4.3v7.3.3v7.4.3+1 more2022-04-27
CVE-2021-38874 [MEDIUM] CVE-2021-38874: IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain bo IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.
nvd
CVE-2021-29776P4MEDIUMCVSS 4.3v7.3.3v7.4.3+1 more2022-04-27
CVE-2021-29776 [MEDIUM] CVE-2021-29776: IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.
nvd
CVE-2020-5032P4MEDIUMCVSS 4.3v7.3v7.42021-02-04
CVE-2020-5032 [MEDIUM] CVE-2020-5032: IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of servic IBM QRadar SIEM 7.3 and 7.4 in some configurations may be vulnerable to a temporary denial of service attack when sent particular payloads. IBM X-Force ID: 194178.
nvd
CVE-2018-1568P4LOWCVSS 3.3v7.2v7.32018-12-05
CVE-2018-1568 [LOW] CWE-200 CVE-2018-1568: IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.
nvd
CVE-2019-4054P4LOWCVSS 3.3v7.2v7.32019-07-17
CVE-2019-4054 [LOW] CVE-2019-4054: IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.
nvd
CVE-2021-20391P4LOWCVSS 3.3v1.0.0v4.1.12021-05-14
CVE-2021-20391 [LOW] CWE-922 CVE-2021-20391: IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which c IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.
nvd
CVE-2020-4787P4LOWCVSS 2.3v7.3.0v7.4.0+4 more2021-01-27
CVE-2020-4787 [LOW] CWE-918 CVE-2020-4787: IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vul IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189224.
nvd
CVE-2025-0164P4LOWCVSS 2.3≥ 7.5, ≤ 7.5.0 UP13 IF012025-09-14
CVE-2025-0164 [LOW] CWE-732 CVE-2025-0164: IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged use IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
nvd
CVE-2018-1725P4LOWCVSS 2.3v7.3.0v7.4+2 more2020-11-05
CVE-2018-1725 [LOW] CVE-2018-1725: IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclo IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440.
nvd
Ibm Qradar Siem vulnerabilities | cvebase