CVE-2025-13995

MEDIUM

IBM QRadar SIEM Information Disclosure

Title source: cna
STIX 2.1

Description

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7266709

Scores

CVSS v3 5.0
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1286
Status published
Products (1)
IBM/QRadar 7.5.0 - 7.5.0 Update Pack 14
Published Mar 19, 2026
Tracked Since Mar 19, 2026