7.8

CVE-2025-33120

Medienbericht

IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmQradar Incident Forensics Version7.5.0 Update-
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_1
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_10
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_11
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_12
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_13
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_2
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_3
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_4
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_5
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_6
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_7
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_8
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_9
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_1
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_10
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_11
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_12
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_13
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_2
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_3
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_4
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_5
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_6
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_7
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_8
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.