CVE-2025-36007

HIGH

IBM Qradar Security Information And E... - Incorrect Privilege Assignment

Title source: rule
STIX 2.1

Description

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
ibm/qradar_security_information_and_event_manager 7.5.0 (16 CPE variants)
Published Oct 27, 2025
Tracked Since Feb 18, 2026