Impact
A flaw in IBM QRadar SIEM 7.5.0 allows a local user to read configuration files that contain potentially sensitive information. The vulnerability permits disclosure of confidential data and is a configuration disclosure weakness classified as CWE‑538.
Affected Systems
IBM QRadar SIEM version 7.5.0, including all update packages up to Update Pack 14, is affected. The issue appears on Linux installations as indicated by the associated CPE entries.
Risk and Exploitability
The CVSS base score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is accessed only by local users and is not listed in the CISA KEV catalog. A local attacker with read permissions could extract sensitive values, though the overall impact depends on the number of accounts with local access and the sensitivity of the data stored.
OpenCVE Enrichment