7.1

CVE-2025-33121

Medienbericht

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12  is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmQradar Security Information And Event Manager Version7.5.0 Update-
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_1
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_10
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_11
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_12
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_2
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_3
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_4
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_5
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_6
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_7
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_8
   LinuxLinux Kernel Version-
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_9
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.564
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.