VYPR

QRadar SIEM

by IBM

CVEs (200)

  • CVE-2019-4210HigApr 8, 2019
    risk 0.53cvss 8.1epss 0.02

    IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.

  • CVE-2016-9724HigMar 7, 2017
    risk 0.53cvss 8.1epss 0.01

    IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM…

  • CVE-2016-2878HigNov 30, 2016
    risk 0.52cvss 8.0epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

  • CVE-2025-36007HigOct 27, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.

  • CVE-2025-33120HigAug 22, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.

  • CVE-2021-39088HigJul 28, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.

  • CVE-2021-20401HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075.

  • CVE-2020-4932HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.

  • CVE-2020-4270HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846.

  • CVE-2019-4508HigJan 10, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.

  • CVE-2016-2880HigMar 1, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.

  • CVE-2016-2879HigMar 1, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a local user to obtain and decrypt user credentials. IBM Reference #: 1997341.

  • CVE-2016-2871HigNov 30, 2016
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.

  • CVE-2020-4509HigJun 4, 2020
    risk 0.50cvss 7.6epss 0.02

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364.

  • CVE-2022-22480HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.

  • CVE-2021-29755HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.00

    IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.

  • CVE-2021-38919HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

  • CVE-2021-38878HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

  • CVE-2021-20400HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.

  • CVE-2021-29750HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.

Page 2 of 10