CVE-2025-36007

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
ibmqradar_security_information_and_event_manager
7.5.0
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_1
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_10
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_11
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_12
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_independent_fix_01
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_13_independent_fix_02
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_2
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_3
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_4
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_5
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_6
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_7
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_8
ibmqradar_security_information_and_event_manager
7.5.0:update_pack_9
𝑥
= Vulnerable software versions