CRITICAL🇵🇱 Wersja polska

CVE-2025-33117

CVSS 9.1v3.1pub. 2025-06-19upd. 2025-07-25

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.

🤖 AI Analysis
How it works

An attacker with administrative privileges in the IBM QRadar SIEM system can modify configuration files responsible for the automatic update mechanism. Through this manipulation, it is possible to substitute or upload a malicious autoupdate file, which is then executed by the system with elevated privileges. The vulnerability is classified as CWE-73 (External Control of File Name or Path), which means that the application does not sufficiently verify the paths or file names specified by user-controlled data.

Impact

An attacker can execute arbitrary system commands on the IBM QRadar SIEM server, which in practice means complete takeover of the system, violation of data confidentiality, and compromising the integrity and availability of the entire SIEM platform.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.ibm.com/support/pages/node/7237317). Additionally, it is recommended to restrict administrative access to the IBM QRadar system only to trusted accounts and monitor changes to configuration files of the update mechanism.

Who is affected

IBM QRadar SIEM in versions 7.5 through 7.5.0 Update Package 12 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • IBM Qradar Security Information And Event Manager

    APP
    Ibm
    7.5.0
  • Linux Kernel

    OS
    Linux
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product

Command Injection w VMware Workspace One Access i Identity Manager