CVE-2025-25021: IBM QRadar Suite Software and IBM Cloud Pak for Security code injection
IBM QRadar SIEM could allow a privileged execute code in case management script creation due to the improper generation of code.
Other sources
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25021?
CVE-2025-25021 is rated as a critical vulnerability due to the potential for privileged code execution.
How do I fix CVE-2025-25021?
To mitigate CVE-2025-25021, upgrade to the latest version of IBM QRadar Suite Software or IBM Cloud Pak for Security that addresses this vulnerability.
What versions are affected by CVE-2025-25021?
CVE-2025-25021 affects IBM QRadar Suite Software versions 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
What kind of impact does CVE-2025-25021 have?
CVE-2025-25021 allows an attacker to execute arbitrary code with elevated privileges, posing significant security risks.
Is authentication required to exploit CVE-2025-25021?
Exploitation of CVE-2025-25021 does not require authentication, making it even more concerning for affected systems.