CVE-2025-36007: IBM QRadar SIEM incorrect privilege assignment
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.
Other sources
IBM QRadar SIEM is vulnerable to privilege escalation due to improper privilege assignment to an update script.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36007?
The severity of CVE-2025-36007 is classified as a privilege escalation vulnerability.
How do I fix CVE-2025-36007?
To fix CVE-2025-36007, it is recommended to apply the latest updates and patches provided by IBM for QRadar SIEM.
Which versions of IBM QRadar SIEM are affected by CVE-2025-36007?
CVE-2025-36007 affects IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 13 Independent Fix 02.
What is the impact of CVE-2025-36007 on IBM QRadar SIEM?
CVE-2025-36007 can allow unauthorized users to escalate their privileges within the IBM QRadar SIEM environment.
Is CVE-2025-36007 being actively exploited?
As of now, there are no public reports indicating that CVE-2025-36007 is being actively exploited in the wild.