CVE-2025-25022: IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure
IBM QRadar SIEM could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
Other sources
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25022?
CVE-2025-25022 has a critical severity rating due to the potential for unauthenticated access to sensitive information.
How do I fix CVE-2025-25022?
To remediate CVE-2025-25022, upgrade IBM QRadar Suite Software to a version higher than 1.11.2.0 and IBM Cloud Pak for Security to a version higher than 1.10.11.0.
Which IBM products are affected by CVE-2025-25022?
CVE-2025-25022 affects IBM QRadar Suite Software versions 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0.
Can CVE-2025-25022 be exploited remotely?
Yes, CVE-2025-25022 can be exploited remotely by an unauthenticated user to access sensitive configuration files.
What is the impact of CVE-2025-25022 on security?
The impact of CVE-2025-25022 is significant, as it allows unauthorized users to obtain sensitive information, potentially leading to further security breaches.