Ad

CVE-2025-36051

MEDIUM CVSS 3.1: 5.5 EPSS 0.01%
Updated Mar 24, 2026
IBM
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-538
Vendor IBM
Public PoC No

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 16

Configuration From (including) Up to (excluding)
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_1:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_10:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_11:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_12:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_13:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_14:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_2:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_3:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_4:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_5:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_6:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_7:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_8:*:*:*:*:*:*
Ibm Qradar_Security_Information_And_Event_Manager
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_9:*:*:*:*:*:*
Linux Linux_Kernel
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*