Impact
This vulnerability occurs in IBM QRadar SIEM when backup files are created with incorrect file permissions. An authenticated user with legitimate credentials can read these backups and potentially gain access to sensitive configuration data and other confidential information. The flaw is classified as CWE‑497, an issue with improper verification of file accessibility that leads to information disclosure. The vulnerability does not allow remote code execution or arbitrary code execution; it solely permits unauthorized reading of backup files.
Affected Systems
IBM QRadar SIEM version 7.5.0 and all interim builds up to 7.5.0 UP15 Interim Fix 006. The affected installations are identified by CPE strings referencing IBM QRadar 7.5.0 and the interim fix 006 package. Administrators using these versions should verify they are running the corrected build.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the moderate to high risk category; the score reflects credentialed users potentially reading sensitive files. The EPSS score of 0.00377 (<1%) indicates a very low exploitation probability, though the vulnerability may still be active. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The attack path requires an authenticated user, but the CVE description does not specify the privilege level required; based on the information, it is inferred that any authenticated user with access to backup files could potentially exploit the issue.
OpenCVE Enrichment