5

CVE-2025-13995

IBM QRadar SIEM Information Disclosure

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmQradar Security Information And Event Manager Version7.5.0 Update-
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_1
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_10
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_11
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_12
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_13
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_14
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_2
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_3
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_4
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_5
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_6
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_7
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_8
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_9
   LinuxLinux Kernel Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.156
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.