Ad

CVE-2025-15051

MEDIUM CVSS 3.1: 5.4 EPSS 0.03%
Updated Mar 23, 2026
Linux
Parameter Value
CVSS 5.4 (MEDIUM)
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Linux
Public PoC No

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 16

Configuration From (including) Up to (excluding)
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_1:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_10:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_11:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_12:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_13:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_14:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_2:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_3:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_4:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_5:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_6:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_7:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_8:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_9:*:*:*:*:*:*
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*