Ibm Qradar Suite vulnerabilities

23 known vulnerabilities affecting ibm/qradar_suite.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM17LOW1

Vulnerabilities

Page 1 of 2
CVE-2025-25021HIGHCVSS 7.2≥ 1.10.12.0, ≤ 1.11.2.02025-06-03
CVE-2025-25021 [HIGH] CWE-94 CVE-2025-25021: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.
nvd
CVE-2025-25022HIGHCVSS 8.8≥ 1.10.12.0, ≤ 1.11.2.02025-06-03
CVE-2025-25022 [CRITICAL] CWE-260 CVE-2025-25022: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
nvd
CVE-2025-25020MEDIUMCVSS 6.5≥ 1.10.12.0, ≤ 1.11.2.02025-06-03
CVE-2025-25020 [MEDIUM] CWE-1287 CVE-2025-25020: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.
nvd
CVE-2025-1334MEDIUMCVSS 4.0≥ 1.10.12.0, ≤ 1.11.2.02025-06-03
CVE-2025-1334 [MEDIUM] CWE-525 CVE-2025-1334: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
nvd
CVE-2025-25019MEDIUMCVSS 6.5≥ 1.10.12.0, ≤ 1.11.2.02025-06-03
CVE-2025-25019 [MEDIUM] CWE-613 CVE-2025-25019: IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.
nvd
CVE-2023-47728HIGHCVSS 7.5≥ 1.10.12.0, < 1.10.23.02024-08-16
CVE-2023-47728 [MEDIUM] CWE-209 CVE-2023-47728: IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.
nvd
CVE-2024-25024MEDIUMCVSS 5.5≥ 1.10.12.0, < 1.10.24.02024-08-15
CVE-2024-25024 [MEDIUM] CWE-312 CVE-2024-25024: IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.
nvd
CVE-2024-28799HIGHCVSS 7.5≥ 1.10.12.0, ≤ 1.10.23.02024-08-14
CVE-2024-28799 [MEDIUM] CWE-214 CVE-2024-28799: IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.
nvd
CVE-2022-38382MEDIUMCVSS 4.1≥ 1.10.12.0, ≤ 1.10.23.02024-08-13
CVE-2022-38382 [MEDIUM] CWE-613 CVE-2022-38382: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672.
nvd
CVE-2024-25023MEDIUMCVSS 5.5≥ 1.10.12.0, < 1.10.23.02024-07-10
CVE-2024-25023 [MEDIUM] CWE-312 CVE-2024-25023: IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 throug IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
nvd
CVE-2022-38383LOWCVSS 3.3≥ 1.10.12.0, ≤ 1.10.21.02024-06-28
CVE-2022-38383 [MEDIUM] CWE-525 CVE-2022-38383: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
nvd
CVE-2023-47726HIGHCVSS 8.8≥ 1.10.12.0, ≤ 1.10.21.02024-06-18
CVE-2023-47726 [HIGH] CWE-1287 CVE-2023-47726: IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 throu IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 272087.
nvd
CVE-2023-47727MEDIUMCVSS 4.3≥ 1.10.12.0, ≤ 1.10.20.02024-05-02
CVE-2023-47727 [MEDIUM] CWE-1287 CVE-2023-47727: IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 throug IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.
nvd
CVE-2022-38386MEDIUMCVSS 5.9≥ 1.10.12.0, ≤ 1.10.19.02024-05-01
CVE-2022-38386 [MEDIUM] CWE-1275 CVE-2022-38386: IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10. IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
nvd
CVE-2023-47731MEDIUMCVSS 5.4≥ 1.10.12.0, ≤ 1.10.19.02024-04-23
CVE-2023-47731 [MEDIUM] CWE-79 CVE-2023-47731: IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2024-28782MEDIUMCVSS 6.5≥ 1.10.12.0, ≤ 1.10.18.02024-04-03
CVE-2024-28782 [MEDIUM] CWE-256 CVE-2024-28782: IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 285698.
nvd
CVE-2023-47742MEDIUMCVSS 5.9≥ 1.10.12.0, ≤ 1.10.18.02024-03-03
CVE-2023-47742 [MEDIUM] CWE-295 CVE-2023-47742: IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information using man in the middle techniques due to not correctly enforcing all aspects of certificate validation in some circumstances. IBM X-Force ID: 272533.
nvd
CVE-2024-22355MEDIUMCVSS 5.9≥ 1.10.12.0, ≤ 1.10.18.02024-03-03
CVE-2024-22355 [MEDIUM] CWE-521 CVE-2024-22355: IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 throug IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 280781.
nvd
CVE-2024-22337MEDIUMCVSS 5.5≥ 1.10.12.0, < 1.10.18.02024-02-17
CVE-2024-22337 [MEDIUM] CWE-532 CVE-2024-22337: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11 IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.
nvd
CVE-2024-22335MEDIUMCVSS 5.5≥ 1.10.12.0, < 1.10.18.02024-02-17
CVE-2024-22335 [MEDIUM] CWE-532 CVE-2024-22335: IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11 IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.
nvd