Get real-time updates on Telegram
CVE-2025-36170: qradar security information and event manager 7.5.0; +1 more affected products
CVE-2025-36170. CVSS 3.1 base score 5.4 (MEDIUM, NVD). EPSS 0.00178 (percentile 0.06683), scored 2026-10-06.
Affected technology
qradar security information and event manager · 7.5.0
ibm
qradar security information and event manager · 7.5.0 · update update_pack_1
ibm
qradar security information and event manager · 7.5.0 · update update_pack_10
ibm
qradar security information and event manager · 7.5.0 · update update_pack_11
ibm
qradar security information and event manager · 7.5.0 · update update_pack_12
ibm
qradar security information and event manager · 7.5.0 · update update_pack_13
ibm
qradar security information and event manager · 7.5.0 · update update_pack_13_interim_fix_01
ibm
qradar security information and event manager · 7.5.0 · update update_pack_13_interim_fix_02
ibm
qradar security information and event manager · 7.5.0 · update update_pack_2
ibm
qradar security information and event manager · 7.5.0 · update update_pack_3
ibm
qradar security information and event manager · 7.5.0 · update update_pack_4
ibm
qradar security information and event manager · 7.5.0 · update update_pack_5
ibm
qradar security information and event manager · 7.5.0 · update update_pack_6
ibm
qradar security information and event manager · 7.5.0 · update update_pack_7
ibm
qradar security information and event manager · 7.5.0 · update update_pack_8
ibm
qradar security information and event manager · 7.5.0 · update update_pack_9
ibm
QRadar SIEM · 7.5.0 through 7.5.0 Update Pack 13
IBM
Description’s affected range: through 7.5.0 Update Pack 13 Independent Fix 02
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · User interaction required
What an attacker can do
An authenticated user can embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Vendor/CNA’s CVSS 3.1 assessment (base score 6.4/10) rates confidentiality and integrity impact as low; availability impact as none. NVD’s CVSS 3.1 assessment (base score 5.4/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-79
- CCR priority
- 21.6 /100 (P4)
- CVSS 3.1
- 5.4 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N · NVD
- EPSS
- 0.00178 · percentile 0.06717 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-36170.html