Impact
IBM QRadar SIEM versions 7.5.0 through 7.6.0.1 are vulnerable to a command injection flaw that permits an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. The vulnerability results in remote code execution on the underlying host, compromising system integrity.
Affected Systems
Affected products are IBM QRadar SIEM 7.5.0, the 7.5.0 UP15 Interim Fix 005 release, and IBM QRadar SIEM 7.6.0.0 and 7.6.0.1.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity, and the EPSS score is not available, suggesting limited data on exploit prevalence. The flaw is not listed in CISA’s KEV catalog, but it requires authenticated privileged access to exploit. An attacker with such credentials could execute any command, so the risk is significant for organizations that delegate privileged roles. The attack vector is inferred to be local operation by a privileged user; indirect remote exploitation is not described.
OpenCVE Enrichment