VYPR

Security Qradar EDR

by IBM

CVEs (17)

  • CVE-2024-45641MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

  • CVE-2023-33861MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

  • CVE-2025-36377MedFeb 17, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36376MedFeb 17, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36379MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2024-45643MedMar 14, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

  • CVE-2023-35006MedJul 10, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

  • CVE-2024-45640MedJan 7, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.

  • CVE-2024-45642MedNov 14, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2023-33860MedJul 10, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the…

  • CVE-2023-33859MedJul 10, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

  • CVE-2024-45100MedJan 7, 2025
    risk 0.32cvss 4.9epss 0.01

    IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.

  • CVE-2024-45644MedMar 19, 2025
    risk 0.31cvss 4.7epss 0.00

    IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

  • CVE-2024-45654MedJan 19, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.

  • CVE-2024-45636MedJun 11, 2026
    risk 0.27cvss 4.1epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.

  • CVE-2024-45638MedMar 14, 2025
    risk 0.27cvss 4.1epss 0.00

    IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

  • CVE-2024-45099LowNov 14, 2024
    risk 0.20cvss 3.1epss 0.00

    IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.