CVE-2025-33117: IBM QRadar SIEM command execution
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.
Other sources
IBM QRadar SIEM could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33117?
CVE-2025-33117 is considered a high severity vulnerability due to the potential for arbitrary command execution by privileged users.
How do I fix CVE-2025-33117?
To fix CVE-2025-33117, ensure that you update IBM QRadar SIEM to version 7.5.0 Update Package 12 IF02 or later.
Who is affected by CVE-2025-33117?
CVE-2025-33117 affects IBM QRadar SIEM versions up to and including 7.5.0 Update Package 12 IF01.
What type of attacks can CVE-2025-33117 enable?
CVE-2025-33117 can enable malicious autoupdates leading to the execution of arbitrary commands on affected systems by privileged users.
When was CVE-2025-33117 disclosed?
CVE-2025-33117 was disclosed recently, highlighting a critical security flaw that demands immediate attention and remediation.