VendorsIBMqradar_security_information_and_event_managerall versions
Vulnerabilities

IBM QRadar Security Information and Event Manager (SIEM)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

192CVEs
CVE-2017-1234
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913.
Published 2017-06-27 · Modified
5.4EPSS 0.007
CVE-2019-4211
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.
Published 2019-07-17 · Modified
5.4EPSS 0.007
CVE-2015-4957
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Published 2016-02-15 · Modified
5.4EPSS 0.006
CVE-2015-7409
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.6 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified field.
Published 2016-01-01 · Modified
5.4EPSS 0.006
CVE-2016-2869
Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.
Published 2016-11-30 · Modified
5.4EPSS 0.006
CVE-2020-4786
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 189221.
Published 2021-01-27 · Modified
5.4EPSS 0.006
CVE-2019-4454
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163618.
Published 2019-11-09 · Modified
5.4EPSS 0.006
CVE-2019-4470
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163779.
Published 2019-11-09 · Modified
5.4EPSS 0.006
CVE-2020-4268
IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 175841.
Published 2020-04-15 · Modified
5.4EPSS 0.006
CVE-2020-4364
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178961.
Published 2020-07-14 · Modified
5.4EPSS 0.006
CVE-2017-1133
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
Published 2017-03-07 · Modified
5.4EPSS 0.005
CVE-2021-29863
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerability is due to an incomplete fix for CVE-2020-4786. IBM X-Force ID: 206087.
Published 2021-12-01 · Modified
5.4EPSS 0.005
CVE-2020-4929
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191706.
Published 2021-05-05 · Modified
5.4EPSS 0.005
CVE-2023-43057
IBM QRadar SIEM cross-site scripting
Published 2023-11-11 · Modified
5.4EPSS 0.004
CVE-2023-26274
IBM QRadar cross-site scripting
Published 2023-06-27 · Modified
5.4EPSS 0.004
CVE-2024-28784
IBM QRadar cross-site scripting
Published 2024-03-27 · Analyzed
5.4EPSS 0.003
CVE-2023-50961
IBM QRadar cross-site scripting
Published 2024-03-27 · Analyzed
5.4EPSS 0.003
CVE-2023-40367
IBM QRadar SIEM cross-site scripting
Published 2023-10-14 · Modified
5.4EPSS 0.003
CVE-2025-36042
IBM QRadar SIEM cross-site scripting
Published 2025-08-22 · Analyzed
5.4EPSS 0.002
CVE-2026-1276
IBM QRadar SIEM Cross-Site Scripting
Published 2026-03-19 · Analyzed
5.4EPSS 0.001
CVE-2025-15051
IBM QRadar SIEM Cross-Site Scripting
Published 2026-03-19 · Analyzed
5.4EPSS 0.001
CVE-2016-2872
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
Published 2016-07-02 · Modified
5.3EPSS 0.018
CVE-2018-1729
IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147708.
Published 2019-04-19 · Modified
5.3EPSS 0.018
CVE-2018-1733
IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.
Published 2019-01-29 · Modified
5.3EPSS 0.017
CVE-2018-2022
IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.
Published 2019-07-17 · Modified
5.3EPSS 0.013
CVE-2019-4559
IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
Published 2020-01-10 · Modified
5.3EPSS 0.011
CVE-2015-2005
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Published 2016-02-15 · Modified
5.3EPSS 0.011
CVE-2021-39041
IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports. IBM X-Force ID: 214028.
Published 2022-07-12 · Modified
5.3EPSS 0.010
CVE-2019-4262
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.
Published 2019-09-26 · Modified
5.3EPSS 0.010
CVE-2016-9720
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.
Published 2017-03-07 · Modified
5.3EPSS 0.009
CVE-2016-9725
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.
Published 2017-03-07 · Modified
5.3EPSS 0.009
CVE-2021-38939
IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.
Published 2022-04-27 · Modified
5.3EPSS 0.008
CVE-2023-50950
IBM QRadar information disclosure
Published 2024-01-17 · Modified
5.3EPSS 0.004
CVE-2015-2007
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files via a crafted URL.
Published 2016-01-03 · Modified
5.0EPSS 0.013
CVE-2014-3091
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2014-10-13 · Modified
5.0EPSS 0.013
CVE-2014-6075
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
Published 2014-11-28 · Modified
5.0EPSS 0.012
CVE-2025-13995
IBM QRadar SIEM Information Disclosure
Published 2026-03-19 · Analyzed
5.0EPSS 0.002
CVE-2016-9722
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
Published 2018-01-10 · Modified
4.91 PoCEPSS 0.120
CVE-2020-4993
IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.
Published 2021-05-05 · Modified
4.9EPSS 0.013
CVE-2021-38936
IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.
Published 2022-07-20 · Modified
4.9EPSS 0.008
← Prev4 / 5Next →