CVE-2025-36170: IBM QRadar SIEM cross-site scripting
IBM QRadar is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36170?
CVE-2025-36170 is classified as a high severity vulnerability due to its potential for stored cross-site scripting and possible credentials disclosure.
How do I fix CVE-2025-36170?
To mitigate CVE-2025-36170, ensure that you update IBM QRadar SIEM to a version that addresses this vulnerability.
What type of vulnerability is CVE-2025-36170?
CVE-2025-36170 is a stored cross-site scripting (XSS) vulnerability affecting IBM QRadar.
Who is affected by CVE-2025-36170?
Authenticated users of IBM QRadar SIEM versions up to 7.5.0 UP13 IF02 are affected by CVE-2025-36170.
What can an attacker do with CVE-2025-36170?
An attacker can potentially embed malicious JavaScript code in the Web UI, leading to unauthorized actions within a trusted session.