Privilege Escalation Vulnerability in IBM QRadar SIEM Product
CVE-2025-36007

7.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
27 October 2025

What is CVE-2025-36007?

IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 are susceptible to a privilege escalation vulnerability caused by incorrect privilege assignment within an update script. This flaw allows attackers to exploit the system permissions, potentially leading to unauthorized access and elevated privileges. Organizations using the affected versions should promptly review their systems and apply necessary patches to mitigate the risk.

Affected Version(s)

QRadar SIEM 7.5.0 <= 7.5.0 UP13 IF02

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

John Zuccato, Rodney Ryan, Chris Shepherd, Vince Dragnea, Ben Goodspeed,Dawid Bak
.