Description
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs in IBM QRadar SIEM when backup files are created with incorrect file permissions. An authenticated user with legitimate credentials can read these backups and potentially gain access to sensitive configuration data and other confidential information. The flaw is classified as CWE‑497, an issue with improper verification of file accessibility that leads to information disclosure. The vulnerability does not allow remote code execution or arbitrary code execution; it solely permits unauthorized reading of backup files.

Affected Systems

IBM QRadar SIEM version 7.5.0 and all interim builds up to 7.5.0 UP15 Interim Fix 006. The affected installations are identified by CPE strings referencing IBM QRadar 7.5.0 and the interim fix 006 package. Administrators using these versions should verify they are running the corrected build.

Risk and Exploitability

The CVSS score of 6.5 places this issue in the moderate to high risk category; the score reflects credentialed users potentially reading sensitive files. The EPSS score of 0.00377 (<1%) indicates a very low exploitation probability, though the vulnerability may still be active. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The attack path requires an authenticated user, but the CVE description does not specify the privilege level required; based on the information, it is inferred that any authenticated user with access to backup files could potentially exploit the issue.

Generated by OpenCVE AI on September 19, 2026 at 18:25 UTC.

Remediation

Vendor Solution

ProductVersionFixIBM QRadar SIEM 7.5.0 7.5.0 UP16 https://www.ibm.com/support/pages/node/7283630


OpenCVE Recommended Actions

  • Install the IBM QRadar SIEM 7.5.0 UP16 product fix to correct the backup file permission issue.
  • Adjust file permissions so that only privileged accounts can read backup files, removing any world‑read or group‑read access granted by default.
  • If the official fix cannot be applied immediately, isolate backup storage from unauthenticated access and monitor backup file read attempts for suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Title IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
First Time appeared Ibm
Ibm qradar
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.5.0up15:interim_fix_006:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T17:40:29.220Z

Reserved: 2025-04-15T17:51:21.700Z

Link: CVE-2025-33141

cve-icon Vulnrichment

Updated: 2026-09-18T17:40:19.536Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:02.520

Modified: 2026-09-18T18:17:47.257

Link: CVE-2025-33141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere