Stored Cross-Site Scripting Vulnerability in IBM QRadar SIEM
CVE-2025-36170
6.4MEDIUM
What is CVE-2025-36170?
IBM QRadar SIEM versions 7.5 up to and including 7.5.0 Update Pack 13 Independent Fix 02 are susceptible to a stored cross-site scripting vulnerability. This flaw permits an authenticated user to introduce harmful JavaScript code into the Web UI, compromising its normal performance. The exploitation of this vulnerability could facilitate the unauthorized disclosure of credentials within a trusted session, ultimately putting sensitive information at risk. Users of affected versions should apply the recommended patches to mitigate this security threat.
Affected Version(s)
QRadar SIEM 7.5.0 <= 7.5.0 Update Pack 13