Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16758 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. |
Solution
IBM strongly encourages customers to update their systems promptly. Please upgrade to at least version 1.11.3.0 according to the following instructions: https://www.ibm.com/docs/en/cloud-paks/cp-security/1.11?topic=installing https://www.ibm.com/docs/en/cloud-paks/cp-security/1.11?topic=upgrading
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7235432 |
|
Tue, 12 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:*:*:*:*:*:*:*:* |
Tue, 03 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. | |
| Title | IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure | |
| First Time appeared |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
| Weaknesses | CWE-260 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_security:1.10.11.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.11.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-26T14:53:06.088Z
Reserved: 2025-01-31T16:26:45.223Z
Link: CVE-2025-25022
Updated: 2025-06-03T15:35:28.114Z
Status : Analyzed
Published: 2025-06-03T16:15:24.437
Modified: 2025-08-12T20:00:40.577
Link: CVE-2025-25022
No data.
OpenCVE Enrichment
No data.
EUVD