IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NIBM Cloud Pak For Security
APPIbm1.10.0.0 – 1.10.11.0IBM Qradar Suite
APPIbm1.10.12.0 – 1.10.19.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-25022CRITICAL9.6PL ✓same product
IBM QRadar Suite / Cloud Pak for Security: ujawnienie danych w plikach konfiguracyjnych
CVE-2021-20578CRITICAL9.8PL ✓same product
IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)
CVE-2021-20538CRITICAL9.1PL ✓same product
Nieprawidłowa autoryzacja w IBM Cloud Pak for Security
CVE-2020-4627CRITICAL9.0PL ✓same product
CSV Injection w IBM Cloud Pak for Security umożliwia zdalne wykonanie kodu
CVE-2025-25021HIGH7.2same product
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0...