
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-56462 is a malicious backup archive upload vulnerability in IBM QRadar SIEM that allows a privileged user to upload a crafted backup archive which, when restored, can be used to gain access to the underlying operating system. It affects IBM QRadar versions 7.5.0 through 7.5.0 UP15 Interim Fix 002. The vulnerability was published on May 27, 2026, with a patch available as of June 5, 2026. It carries a CVSS v3.1 base score of 8.8 (High) per NVD scoring, or 7.2 (High) per IBM/ENISA scoring with higher privilege requirements (IBM Advisory, Red Hat CVE).
The vulnerability is classified under CWE-530 (Exposure of Backup File to an Unauthorized Control Sphere) and CWE-552 (Files or Directories Accessible to External Parties), indicating insufficient validation and access controls around backup archive handling. An attacker with privileged (low-privilege per NVD, or high-privilege per IBM) network access can upload a specially crafted backup archive through QRadar's backup management interface. When the malicious archive is subsequently restored by the system, it can execute arbitrary code or place malicious files that grant access to the underlying operating system. No user interaction is required beyond the initial upload and restore action (IBM Advisory, Red Hat CVE).
Successful exploitation results in full compromise of the underlying operating system hosting IBM QRadar, with high impact to confidentiality, integrity, and availability. An attacker achieving OS-level access on a QRadar SIEM appliance could exfiltrate sensitive security event data, tamper with log integrity, disable security monitoring, and potentially use the compromised SIEM as a pivot point for lateral movement within the enterprise network. Given QRadar's role as a central security monitoring platform, compromise could blind defenders to ongoing attacks across the environment (IBM Advisory).
curl, wget, nc); unexpected outbound network connections from the QRadar host.IBM has released a patch addressing this vulnerability; organizations should update IBM QRadar beyond version 7.5.0 UP15 Interim Fix 002 by applying the fix available at the IBM support page (IBM Advisory). As interim mitigations, implement strict role-based access controls to limit which accounts can upload and restore backup archives, restricting this capability to the minimum necessary administrators. Network access to QRadar backup management functions should be restricted to trusted administrative hosts only. Monitor and alert on all backup upload and restoration activities for anomalous behavior.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."