5.5

CVE-2025-36051

Medienbericht

IBM QRadar SIEM Information Disclosure

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update -
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_1
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_10
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_11
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_12
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_13
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_14
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_2
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_3
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_4
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_5
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_6
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_7
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_8
   Linux ≫ Linux Kernel Version -
Ibm ≫ Qradar Security Information And Event Manager Version 7.5.0 Update update_pack_9
   Linux ≫ Linux Kernel Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.011
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
IBM 6.2 2.5 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.03.2026 10:06
https://www.ibm.com/support/pages/node/7266709
Vendor Advisory