Unrated severityNVD Advisory· Published Jun 3, 2025· Updated Aug 24, 2025
IBM QRadar Suite Software and IBM Cloud Pak for Security session fixation
CVE-2025-25019
Description
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.
Affected products
4cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:*range: 1.10.0.0
- (no CPE)range: >=1.10.0.0 <=1.10.11.0
cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:*range: 1.10.12.0
- (no CPE)range: >=1.10.12.0 <=1.11.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7235432mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.