Impact
IBM QRadar SIEM versions 7.5.0 through the interim fix 005 embed hard‑coded credentials, such as passwords or cryptographic keys, that the product uses for inbound authentication, outbound communications to external services, or encryption of internal data. Because the credentials are in the code base, an attacker who discovers them can authenticate to or decrypt components that trust those credentials, enabling unauthorized read or write access to sensitive security data or administrative functions.
Affected Systems
Affected products are IBM QRadar SIEM 7.5.0 and its interim fix releases, specifically 7.5.0, 7.5.0 UP15, and interim fix 005. The CPE entries include `cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*` and its corresponding interim fix. Admins should verify that their deployments match these identifiers to confirm exposure.
Risk and Exploitability
The CVSS base score of 6.7 indicates moderate severity. The exploitability score is not reported, and the vulnerability has not been listed in the CISA KEV catalog. Given the nature of the flaw, an attacker who can acquire the hard‑coded values—either by reverse engineering the installer, inspecting the source, or obtaining a system snapshot—can use them to authenticate or gain elevated rights to the SIEM, with a high likelihood of success once the credentials are known. The attack vector is likely local or remote, depending on whether the product’s authentication endpoints are exposed, but the presence of hard‑coded secrets is inherently risky and should be treated as a high‑risk condition.
OpenCVE Enrichment