VendorsIBMqradar_security_information_and_event_manager7.5.0
Vulnerabilities

IBM QRadar Security Information and Event Manager (SIEM) 7.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2021-38869
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
Published 2022-04-27 · Modified
9.8EPSS 0.009
CVE-2026-10025
IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
Published 2026-08-05 · Analyzed
9.8EPSS 0.006
CVE-2025-33117
IBM QRadar SIEM command execution
Published 2025-06-19 · Analyzed
9.1EPSS 0.006
CVE-2026-13477
IBM QRadar SIEM is vulnerable to remote code execution by privileged users
Published 2026-08-05 · Analyzed
8.8EPSS 0.005
CVE-2024-56462
IBM QRadar SIEM is vulnerable to using components with known vulnerabilities
Published 2026-05-27 · Analyzed
8.8EPSS 0.005
CVE-2023-22875
IBM Security QRadar SIEM information disclosure
Published 2023-01-17 · Modified
8.4EPSS 0.003
CVE-2023-50949
IBM QRadar improper certificate validation
Published 2024-04-11 · Analyzed
8.1EPSS 0.003
CVE-2021-39088
IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.
Published 2022-07-28 · Modified
7.8EPSS 0.002
CVE-2025-33120
IBM QRadar SIEM privilege escalation
Published 2025-08-22 · Analyzed
7.8EPSS 0.002
CVE-2025-36007
IBM QRadar SIEM incorrect privilege assignment
Published 2025-10-27 · Analyzed
7.8EPSS 0.001
CVE-2021-38878
IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
Published 2022-04-27 · Modified
7.5EPSS 0.012
CVE-2021-38919
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021
Published 2022-04-27 · Modified
7.5EPSS 0.011
CVE-2022-22480
IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.
Published 2022-10-07 · Modified
7.5EPSS 0.008
CVE-2021-29755
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
Published 2022-07-20 · Modified
7.5EPSS 0.005
CVE-2022-34351
IBM QRadar SIEM information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.004
CVE-2023-26276
IBM QRadar information disclosure
Published 2023-06-27 · Modified
7.5EPSS 0.004
CVE-2023-30994
IBM QRadar SIEM information disclosure
Published 2023-10-14 · Modified
7.5EPSS 0.002
CVE-2022-43863
IBM QRadar SIEM privilege escalation
Published 2023-03-22 · Modified
7.2EPSS 0.007
CVE-2025-33121
IBM QRadar SIEM XML external entity injection
Published 2025-06-19 · Analyzed
7.1EPSS 0.005
CVE-2024-27269
IBM QRadar SIEM information disclosure
Published 2024-05-10 · Analyzed
6.8EPSS 0.004
CVE-2023-47146
IBM QRadar SIEM information disclosure
Published 2023-12-19 · Modified
6.5EPSS 0.007
CVE-2022-34352
IBM QRadar information disclosure
Published 2023-06-27 · Modified
6.5EPSS 0.006
CVE-2023-43041
IBM QRadar information disclosure
Published 2023-10-29 · Modified
6.5EPSS 0.005
CVE-2025-33119
IBM QRadar SIEM Information Disclosure
Published 2025-11-12 · Analyzed
6.5EPSS 0.002
CVE-2024-28786
IBM QRadar SIEM information disclosure
Published 2025-01-27 · Analyzed
6.5EPSS 0.002
CVE-2024-47107
IBM QRadar SIEM cross-site scripting
Published 2024-12-07 · Analyzed
6.4EPSS 0.002
CVE-2025-33118
IBM QRadar SIEM cross-site scripting
Published 2025-08-01 · Analyzed
6.4EPSS 0.002
CVE-2025-33097
IBM QRadar SIEM cross-site scripting
Published 2025-07-15 · Analyzed
6.4EPSS 0.002
CVE-2025-36138
IBM QRadar SIEM cross-site scripting
Published 2025-10-27 · Analyzed
6.4EPSS 0.002
CVE-2025-36170
IBM QRadar SIEM cross-site scripting
Published 2025-10-27 · Analyzed
6.4EPSS 0.002
CVE-2025-36050
IBM QRadar SIEM information disclosure
Published 2025-06-19 · Analyzed
6.2EPSS 0.002
CVE-2025-36051
IBM QRadar SIEM Information Disclosure
Published 2026-03-19 · Analyzed
6.2EPSS 0.001
CVE-2022-30613
IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.
Published 2022-10-07 · Modified
5.5EPSS 0.002
CVE-2022-22424
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
Published 2022-07-20 · Modified
5.5EPSS 0.002
CVE-2023-43057
IBM QRadar SIEM cross-site scripting
Published 2023-11-11 · Modified
5.4EPSS 0.004
CVE-2023-26274
IBM QRadar cross-site scripting
Published 2023-06-27 · Modified
5.4EPSS 0.004
CVE-2024-28784
IBM QRadar cross-site scripting
Published 2024-03-27 · Analyzed
5.4EPSS 0.003
CVE-2023-50961
IBM QRadar cross-site scripting
Published 2024-03-27 · Analyzed
5.4EPSS 0.003
CVE-2023-40367
IBM QRadar SIEM cross-site scripting
Published 2023-10-14 · Modified
5.4EPSS 0.003
CVE-2025-36042
IBM QRadar SIEM cross-site scripting
Published 2025-08-22 · Analyzed
5.4EPSS 0.002
1 / 2Next →