CVE-2025-33120: IBM QRadar SIEM privilege escalation
IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.
Other sources
IBM QRadar SIEM could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33120?
CVE-2025-33120 is considered a medium severity vulnerability that allows privilege escalation in IBM QRadar SIEM.
How do I fix CVE-2025-33120?
To fix CVE-2025-33120, reconfigure the affected cronjob to ensure it does not execute with unnecessary privileges.
Who is affected by CVE-2025-33120?
IBM QRadar SIEM versions 7.5 through 7.5.0 UP13 are affected by CVE-2025-33120.
What type of vulnerability is CVE-2025-33120?
CVE-2025-33120 is a privilege escalation vulnerability due to a misconfigured cronjob.
Can unprivileged users exploit CVE-2025-33120?
Yes, an authenticated unprivileged user could exploit CVE-2025-33120 to escalate their privileges.