CVE-2025-36007

HIGH

IBM QRadar SIEM 7.5-7.5.0 Update Pack 13 Independent Fix 02 - Privilege Escalation via Update Script

Title source: llm
STIX 2.1

Description

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7249277

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
ibm/qradar_security_information_and_event_manager 7.5.0 (16 CPE variants)
Published Oct 27, 2025
Tracked Since Feb 18, 2026