Known vulnerabilities in IBM Qradar SIEM 7.5.0 Update Pack 12 IF02 - page 10

Version: 7.5.0 Update Pack 12 IF02
Software CPE: cpe:2.3:a:ibm_corporation:ibm_qradar_siem:*:*:*:*:*:*:*:*
Total vulnerabilities: 223
Public exploits: 13
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting IBM Qradar SIEM version 7.5.0 Update Pack 12 IF02 IBM Qradar SIEM 7.5.0 Update Pack 12 IF02 is affected by 223 vulnerabilities: 1 critical, 28 high, 77 medium, 117 low Critical High Medium Low

Vulnerabilities (223)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114428 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-36042
CWE-79 Medium
No
No
7.5.0 Update Pack 13 IF01 26.08.2025 SB2025082608
#VU114427 - Execution with Unnecessary Privileges
CVE-2025-33120
CWE-250 Medium
No
No
7.5.0 Update Pack 13 IF01 26.08.2025 SB2025082608
#VU112255 - Deserialization of Untrusted Data
CVE-2025-27818
CWE-502 Medium
No
No
7.5.0 Update Pack 13 04.07.2025 SB20250704102
SB2025070708
SB2025080519
and 16 more
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Public exploit available
No
7.5.0 Update Pack 13 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU112067 - Protection Mechanism Failure
CVE-2025-32462
CWE-693 Low
Public exploit available
No
7.5.0 Update Pack 13 01.07.2025 SB2025070109
SB2025070111
SB2025070112
and 42 more
#VU111970 - Expected Behavior Violation
CVE-2025-4435
CWE-440 Low
No
No
7.5.0 Update Pack 13 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 59 more
#VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12718
CWE-22 Medium
No
No
7.5.0 Update Pack 13 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 62 more
#VU111968 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4138
CWE-59 High
Public exploit available
No
7.5.0 Update Pack 13 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 64 more
#VU111967 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4330
CWE-59 High
No
No
7.5.0 Update Pack 13 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 63 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Public exploit available
No
7.5.0 Update Pack 13 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more
#VU111913 - Integer overflow
CVE-2024-23337
CWE-190 Medium
No
No
7.5.0 Update Pack 13 IF01 25.06.2025 SB2025032035
SB2025070824
SB2025070826
and 29 more
#VU111389 - Improper Access Control
CVE-2025-6020
CWE-284 Low
No
No
7.5.0 Update Pack 13 19.06.2025 SB2025061987
SB2025061992
SB20250619103
and 69 more
#VU109844 - Untrusted Search Path
CVE-2025-4802
CWE-426 Low
No
No
7.5.0 Update Pack 13 27.05.2025 SB2025052725
SB2025052735
SB2025052910
and 36 more
#VU104950 - Use After Free
CVE-2025-21764
CWE-416 Low
No
No
7.5.0 Update Pack 13 27.02.2025 SB2025022748
SB2025040917
SB2025040929
and 68 more
#VU103980 - Resource exhaustion
CVE-2024-12133
CWE-400 Medium
No
No
7.5.0 Update Pack 13 14.02.2025 SB2025021428
SB2025021429
SB2025021430
and 78 more
#VU100780 - Exposure of sensitive information to an unauthorized actor
CVE-2024-31141
CWE-200 Medium
No
No
7.5.0 Update Pack 13 21.11.2024 SB2024112150
SB2024120226
SB2024120331
and 34 more
#VU100714 - NULL Pointer Dereference
CVE-2024-53064
CWE-476 Low
No
No
7.5.0 Update Pack 13 20.11.2024 SB2024112041
SB20250115100
SB2025011731
and 24 more
#VU100622 - Out-of-bounds read
CVE-2024-50301
CWE-125 Low
No
No
7.5.0 Update Pack 13 19.11.2024 SB2024111933
SB2024112401
SB2024112933
and 69 more
#VU98025 - Resource exhaustion
CVE-2024-47554
CWE-400 Medium
No
No
7.5.0 Update Pack 13 03.10.2024 SB2024100352
SB2024100421
SB2024101007
and 132 more
#VU96413 - Use After Free
CVE-2022-48919
CWE-416 Low
No
No
7.5.0 Update Pack 13 22.08.2024 SB2024082217
SB2024091076
SB2024091077
and 18 more


Showing elements 181 - 200 out of 223