PT-2025-44012 · Ibm · Ibm Qradar Siem
Fahimhusain Raydurg
·
Published
2025-10-27
·
Updated
2025-12-15
·
CVE-2025-36138
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 13 Independent Fix 02
Description
IBM QRadar SIEM is susceptible to stored cross-site scripting. An authenticated user can inject arbitrary JavaScript code into the Web UI, potentially modifying the intended functionality and leading to credentials disclosure within a trusted session. The vulnerability allows for the embedding of malicious scripts that can compromise the integrity of the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Privilege Assignment
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Qradar Siem