5.4

CVE-2025-36042

Medienbericht

IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmQradar Incident Forensics Version7.5.0 Update-
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_1
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_10
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_11
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_12
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_13
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_2
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_3
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_4
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_5
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_6
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_7
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_8
IbmQradar Incident Forensics Version7.5.0 Updateupdate_pack_9
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_1
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_10
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_11
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_12
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_13
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_2
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_3
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_4
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_5
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_6
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_7
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_8
IbmQradar Security Information And Event Manager Version7.5.0 Updateupdate_pack_9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.076
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.