CVE-2025-36042: IBM QRadar SIEM cross-site scripting
IBM QRadar Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36042?
CVE-2025-36042 is considered a high severity vulnerability due to its potential for allowing credential disclosure via cross-site scripting.
How do I fix CVE-2025-36042?
To fix CVE-2025-36042, update IBM QRadar SIEM to a version beyond 7.5.0 UP13 that addresses the cross-site scripting vulnerability.
Who is affected by CVE-2025-36042?
All authenticated users of IBM QRadar SIEM versions up to 7.5.0 UP13 are affected by CVE-2025-36042.
What kind of attacks can occur due to CVE-2025-36042?
CVE-2025-36042 can lead to attacks where an authenticated user can inject malicious JavaScript to alter functionality or extract sensitive data.
Is CVE-2025-36042 easy to exploit?
Exploiting CVE-2025-36042 requires authenticated access, making it easier for users with access rights to leverage the vulnerability.