CVE-2025-36376
17.02.2026, 21:22
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | security_qradar_edr | 3.12.0 ≤ 𝑥 < 3.12.24 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration