Description
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Published: 2026-09-04
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Now
AI Analysis

Impact

IBM QRadar SIEM versions 7.5.0 through the interim fix 005 embed hard‑coded credentials, such as passwords or cryptographic keys, that the product uses for inbound authentication, outbound communications to external services, or encryption of internal data. Because the credentials are in the code base, an attacker who discovers them can authenticate to or decrypt components that trust those credentials, enabling unauthorized read or write access to sensitive security data or administrative functions.

Affected Systems

Affected products are IBM QRadar SIEM 7.5.0 and its interim fix releases, specifically 7.5.0, 7.5.0 UP15, and interim fix 005. The CPE entries include `cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*` and its corresponding interim fix. Admins should verify that their deployments match these identifiers to confirm exposure.

Risk and Exploitability

The CVSS base score of 6.7 indicates moderate severity. The exploitability score is not reported, and the vulnerability has not been listed in the CISA KEV catalog. Given the nature of the flaw, an attacker who can acquire the hard‑coded values—either by reverse engineering the installer, inspecting the source, or obtaining a system snapshot—can use them to authenticate or gain elevated rights to the SIEM, with a high likelihood of success once the credentials are known. The attack vector is likely local or remote, depending on whether the product’s authentication endpoints are exposed, but the presence of hard‑coded secrets is inherently risky and should be treated as a high‑risk condition.

Generated by OpenCVE AI on September 4, 2026 at 16:41 UTC.

Remediation

Vendor Solution

IBM strongly encourages customers to update their systems promptly. ProductVersionFixIBM QRadar SIEM 7.5.0  7.5.0 UP15 IF06 https://www.ibm.com/support/pages/node/7283124


OpenCVE Recommended Actions

  • Upgrade to IBM QRadar SIEM 7.5.0 ProductVersionFixIBM QRadar SIEM 7.5.0 or later (including interim fix 005) to remove hard‑coded credentials.
  • Replace any default credentials or keys that may have been compromised with unique, randomly generated secrets, and enforce password complexity and rotation policies.
  • Conduct a comprehensive audit of authentication and encryption logs to detect unauthorized use of the hard‑coded credentials, and review access controls to ensure least privilege.

Generated by OpenCVE AI on September 4, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Title QRadar contains hard-coded credentials
First Time appeared Ibm
Ibm qradar
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar:7.5.0up15:interim_fix_005:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qradar
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T15:55:43.615Z

Reserved: 2026-04-03T23:45:57.189Z

Link: CVE-2026-5522

cve-icon Vulnrichment

Updated: 2026-09-04T15:55:26.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T16:17:25.870

Modified: 2026-09-08T14:17:08.940

Link: CVE-2026-5522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:45:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials