IBM QRadar SIEM does not invalidate session after a logout which could allow a user to impersonate another user on the system.
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.
IBM QRadar Suite allows web pages to be stored locally which can be read by another user on the system.