Description
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
Published: 2026-03-19
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A flaw in IBM QRadar SIEM 7.5.0 allows a local user to read configuration files that contain potentially sensitive information. The vulnerability permits disclosure of confidential data and is a configuration disclosure weakness classified as CWE‑538.

Affected Systems

IBM QRadar SIEM version 7.5.0, including all update packages up to Update Pack 14, is affected. The issue appears on Linux installations as indicated by the associated CPE entries.

Risk and Exploitability

The CVSS base score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is accessed only by local users and is not listed in the CISA KEV catalog. A local attacker with read permissions could extract sensitive values, though the overall impact depends on the number of accounts with local access and the sensitivity of the data stored.

Generated by OpenCVE AI on March 24, 2026 at 22:52 UTC.

Remediation

Vendor Solution

ProductVersionFixIBM QRadar SIEM 7.5.0 7.5.0 UP15 https://www.ibm.com/support/fixcentral/swg/selectFixes  ( Release Notes https://www.ibm.com/support/pages/node/7257011 )


OpenCVE Recommended Actions

  • Apply IBM QRadar SIEM 7.5.0 Update Pack 15 to remove sensitive data from configuration files.
  • If an immediate update is not possible, tighten file permissions on the affected configuration files so that only privileged system accounts can read them.
  • After remediation, verify that sensitive information is no longer present in the configuration files and monitor IBM advisory releases for additional guidance.

Generated by OpenCVE AI on March 24, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_10:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_11:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_12:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_13:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_1:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_2:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_3:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_4:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_5:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_6:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_7:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_8:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_9:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Thu, 19 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
Description IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user.
Title IBM QRadar SIEM Information Disclosure
First Time appeared Ibm
Ibm qradar Security Information And Event Manager
Weaknesses CWE-538
CPEs cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.5.0:update_pack_14:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar Security Information And Event Manager
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Qradar Security Information And Event Manager
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-19T16:07:34.904Z

Reserved: 2025-04-15T21:16:11.324Z

Link: CVE-2025-36051

cve-icon Vulnrichment

Updated: 2026-03-19T16:07:30.807Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-19T03:16:01.460

Modified: 2026-03-24T21:13:27.020

Link: CVE-2025-36051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T11:55:27Z

Weaknesses