Impact
IBM QRadar SIEM versions 7.6.0.0–7.6.0.1 and 7.5.0–7.5.0 UP 15 Interim Fix 005 contain an XML External Entity (XXE) injection flaw in the parseXmlPayload() function. Attacks allow a remote actor to send crafted XML data to the syslog intake on port 514 (UDP/TCP) without authentication. The vulnerability can lead to disclosure of sensitive configuration files or arbitrary local files, potentially compromising system integrity and confidentiality.
Affected Systems
All IBM QRadar SIEM installations running versions 7.5.x (including 7.5.0 through 7.5.0 UP15) and 7.6.x (7.6.0.0–7.6.0.1) are affected. Vendors advise applying the fixed releases: 7.6.0.2 and the 7.5.0 UP15 IF05 Hotfix (20260715231428) to mitigate the issue.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS data is unavailable, but the vulnerability is exploitable from the internet via the unprotected syslog port, and it is not currently listed in the CISA KEV catalog. Attackers would need to send malicious XML to the syslog service; no privileged credentials are required, making the risk accessible to remote attackers within network reach of port 514.
OpenCVE Enrichment