CVE-2025-33119

MEDIUM

IBM QRadar SIEM <7.5.0 UP14 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7250932

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-260
Status published
Products (1)
ibm/qradar_security_information_and_event_manager 7.5.0 (17 CPE variants)
Published Nov 12, 2025
Tracked Since Feb 18, 2026