CVE-2025-33121: IBM QRadar SIEM XML external entity injection
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM QRadar SIEM is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33121?
CVE-2025-33121 has a high severity due to its potential for XML external entity injection that can lead to data exposure or resource exhaustion.
How do I fix CVE-2025-33121?
To fix CVE-2025-33121, apply the latest security updates provided by IBM for QRadar SIEM.
What is the impact of CVE-2025-33121?
Exploitation of CVE-2025-33121 could allow a remote attacker to access sensitive data or cause significant memory resource consumption.
Is CVE-2025-33121 present in all versions of IBM QRadar SIEM?
CVE-2025-33121 specifically affects IBM QRadar SIEM versions 7.5 through 7.5.0 Update Package 12.
Can CVE-2025-33121 be exploited remotely?
Yes, CVE-2025-33121 can be exploited remotely by an attacker who sends malicious XML data.