VendorsIBMqradar_security_information_and_event_managerall versions
Vulnerabilities

IBM QRadar Security Information and Event Manager (SIEM)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

192CVEs
CVE-2017-1722
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811.
Published 2018-04-26 · Modified
6.5EPSS 0.011
CVE-2020-4151
IBM QRadar SIEM 7.3.0 through 7.3.3 could allow an authenticated attacker to perform unauthorized actions due to improper input validation. IBM X-Force ID: 174201.
Published 2020-04-14 · Modified
6.5EPSS 0.011
CVE-2014-4833
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.
Published 2014-10-19 · Modified
6.5EPSS 0.011
CVE-2014-4824
SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2014-09-18 · Modified
6.5EPSS 0.010
CVE-2016-2881
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.
Published 2016-11-30 · Modified
6.5EPSS 0.009
CVE-2021-29880
IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
Published 2021-08-13 · Modified
6.5EPSS 0.009
CVE-2016-9750
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.
Published 2017-05-15 · Modified
6.5EPSS 0.008
CVE-2020-4883
IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X-Force ID: 190907.
Published 2021-05-05 · Modified
6.5EPSS 0.008
CVE-2016-9729
IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.
Published 2017-03-07 · Modified
6.5EPSS 0.008
CVE-2023-47146
IBM QRadar SIEM information disclosure
Published 2023-12-19 · Modified
6.5EPSS 0.007
CVE-2022-34352
IBM QRadar information disclosure
Published 2023-06-27 · Modified
6.5EPSS 0.006
CVE-2023-43041
IBM QRadar information disclosure
Published 2023-10-29 · Modified
6.5EPSS 0.005
CVE-2020-4980
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as well as data at rest. IBM X-Force ID: 192539.
Published 2021-07-16 · Modified
6.5EPSS 0.003
CVE-2025-33119
IBM QRadar SIEM Information Disclosure
Published 2025-11-12 · Analyzed
6.5EPSS 0.002
CVE-2024-28786
IBM QRadar SIEM information disclosure
Published 2025-01-27 · Analyzed
6.5EPSS 0.002
CVE-2024-47107
IBM QRadar SIEM cross-site scripting
Published 2024-12-07 · Analyzed
6.4EPSS 0.002
CVE-2025-33118
IBM QRadar SIEM cross-site scripting
Published 2025-08-01 · Analyzed
6.4EPSS 0.002
CVE-2025-33097
IBM QRadar SIEM cross-site scripting
Published 2025-07-15 · Analyzed
6.4EPSS 0.002
CVE-2025-36170
IBM QRadar SIEM cross-site scripting
Published 2025-10-27 · Analyzed
6.4EPSS 0.002
CVE-2025-36138
IBM QRadar SIEM cross-site scripting
Published 2025-10-27 · Analyzed
6.4EPSS 0.002
CVE-2025-36050
IBM QRadar SIEM information disclosure
Published 2025-06-19 · Analyzed
6.2EPSS 0.002
CVE-2025-36051
IBM QRadar SIEM Information Disclosure
Published 2026-03-19 · Analyzed
6.2EPSS 0.001
CVE-2017-1623
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121.
Published 2018-01-10 · Modified
6.1EPSS 0.010
CVE-2018-2021
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.
Published 2019-07-17 · Modified
6.1EPSS 0.009
CVE-2019-4581
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167239.
Published 2019-11-09 · Modified
6.1EPSS 0.009
CVE-2020-4513
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182368.
Published 2020-07-14 · Modified
6.1EPSS 0.007
CVE-2017-1724
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
Published 2018-04-26 · Modified
6.1EPSS 0.007
CVE-2021-20397
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196017.
Published 2021-05-05 · Modified
6.1EPSS 0.007
CVE-2016-9723
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
Published 2017-03-07 · Modified
6.1EPSS 0.006
CVE-2021-29849
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281.
Published 2021-12-01 · Modified
6.1EPSS 0.006
CVE-2016-9972
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208.
Published 2017-06-27 · Modified
5.9EPSS 0.015
CVE-2021-29779
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033.
Published 2021-12-01 · Modified
5.9EPSS 0.012
CVE-2019-4264
IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
Published 2019-05-29 · Modified
5.9EPSS 0.010
CVE-2019-4594
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-ForceID: 167810.
Published 2020-04-15 · Modified
5.9EPSS 0.008
CVE-2018-1612
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164.
Published 2018-07-17 · Modified
5.81 PoCEPSS 0.557
CVE-2019-4654
IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-ForceID: 170965.
Published 2020-04-15 · Modified
5.8EPSS 0.004
CVE-2020-4274
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.
Published 2020-04-15 · Modified
5.5EPSS 0.009
CVE-2017-1624
IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122.
Published 2018-04-04 · Modified
5.5EPSS 0.006
CVE-2022-30613
IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.
Published 2022-10-07 · Modified
5.5EPSS 0.002
CVE-2022-22424
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
Published 2022-07-20 · Modified
5.5EPSS 0.002
← Prev3 / 5Next →