Sensitive Information Exposure in IBM QRadar SIEM
CVE-2025-36050

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 June 2025

What is CVE-2025-36050?

IBM QRadar SIEM versions 7.5 up to and including Update Package 12 are susceptible to a vulnerability where sensitive information may be stored in log files. This data can potentially be accessed by local users without proper authorization, raising concerns about the confidentiality and integrity of sensitive information logged by the system. Organizations utilizing affected versions must assess their exposure and implement appropriate security measures as needed.

Affected Version(s)

QRadar SIEM 7.5 <= 7.5.0 Update Pack 12

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

John Zuccato, Rodney Ryan, Chris Shepherd, Vince Dragnea, Ben Goodspeed, Dawid Bak
.
CVE-2025-36050 : Sensitive Information Exposure in IBM QRadar SIEM