CRITICAL🇵🇱 Wersja polska

CVE-2025-25022

CVSS 9.6v3.1pub. 2025-06-03upd. 2025-08-12

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-260 (Password in Configuration File) consists of sensitive data — potentially including passwords or keys — being stored in configuration files in a manner accessible without authentication. An unauthenticated user with network access to the environment (AV:A vector — access from local/adjacent network) can read these files and obtain critical data. The lack of authentication requirement (PR:N) and user interaction (UI:N) means that the attack can be performed in a fully automated manner.

Impact

An attacker can obtain highly sensitive information from configuration files, which may lead to further system takeover, privilege escalation, or lateral movement within the infrastructure. The scope of the vulnerability includes complete breach of confidentiality, integrity, and availability (S:C, C:H, I:H, A:H).

Mitigation & patch

Patches available from the vendor should be applied according to the references: https://www.ibm.com/support/pages/node/7235432

Who is affected

IBM QRadar Suite Software in versions from 1.10.12.0 to 1.11.2.0 and IBM Cloud Pak for Security in versions from 1.10.0.0 to 1.10.11.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • IBM Cloud Pak For Security

    APP
    Ibm
    1.10.0.0 – 1.10.11.0
  • IBM Qradar Suite

    APP
    Ibm
    1.10.12.0 – 1.11.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-20578CRITICAL9.8PL ✓same product

IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)

CVE-2021-20538CRITICAL9.1PL ✓same product

Nieprawidłowa autoryzacja w IBM Cloud Pak for Security

CVE-2020-4627CRITICAL9.0PL ✓same product

CSV Injection w IBM Cloud Pak for Security umożliwia zdalne wykonanie kodu

CVE-2025-25021HIGH7.2same product

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0...

CVE-2023-47726HIGH7.1same product

IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21...