CVE-2025-36051
IBM QRadar SIEM vulnerability analysis and mitigation

Overview

CVE-2025-36051 is an information disclosure vulnerability in IBM QRadar SIEM that allows local users to read sensitive data stored in configuration files. It affects IBM QRadar SIEM versions 7.5.0 through 7.5.0 Update Package 14. The vulnerability was published on March 19, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium), reflecting a local attack vector with high confidentiality impact but no integrity or availability impact (IBM Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory), meaning IBM QRadar SIEM improperly stores sensitive data — such as credentials, API keys, or database passwords — in configuration files that are readable by local, low-privileged users. Exploitation requires only local file system access with standard user privileges; no authentication bypass, special permissions, or user interaction is needed. An attacker with a local account on the QRadar system can simply read the affected configuration files to extract sensitive information (IBM Advisory, Feedly).

Impact

Successful exploitation exposes sensitive information stored in QRadar SIEM configuration files, potentially including credentials, API keys, and database passwords. Since QRadar SIEM is a security monitoring platform with broad access to network telemetry and integrated systems, credential exposure could enable lateral movement to connected infrastructure or allow an attacker to tamper with security monitoring capabilities. The impact is limited to confidentiality — there is no direct integrity or availability impact from this vulnerability alone (IBM Advisory).

Exploitation steps

  1. Gain Local Access: Obtain a local user account on the IBM QRadar SIEM system, either through legitimate access, social engineering, or by leveraging a separate initial access vulnerability.
  2. Identify Configuration Files: Navigate the QRadar file system to locate configuration files known to store application settings, credentials, or API keys (e.g., directories under /opt/qradar/ or similar QRadar installation paths).
  3. Read Sensitive Data: Use standard file read commands (e.g., cat, less, grep) to extract sensitive information such as database passwords, API keys, or service credentials from the accessible configuration files.
  4. Leverage Extracted Credentials: Use the harvested credentials to authenticate to connected systems, databases, or APIs, potentially enabling lateral movement or further compromise of the environment (IBM Advisory).

Indicators of compromise

  • File System: Unexpected access to QRadar configuration files in directories such as /opt/qradar/conf/ or similar installation paths by non-administrative local users.
  • Logs: Audit log entries showing local user accounts reading configuration files outside of normal administrative activity; OS-level file access audit events (e.g., Linux auditd logs) for sensitive config file reads.
  • Process: Unusual shell processes (e.g., cat, grep, strings) executed by non-privileged users targeting QRadar configuration directories.

Mitigation and workarounds

IBM has released a patch addressing this vulnerability; users should apply the update available at the IBM support page (node/7266709), which covers all affected versions from 7.5.0 through 7.5.0 Update Package 14. As interim mitigations, administrators should restrict file system permissions on QRadar configuration directories to limit read access to only necessary administrative accounts, enforce the principle of least privilege for local user accounts, and enable file access auditing to detect unauthorized reads of sensitive configuration files (IBM Advisory).

Community reactions

Heise (a German technology news outlet) covered the vulnerability, noting that SSH sessions in IBM QRadar SIEM could be compromised as a result of the exposed configuration data (Heise). Tenable published a Nessus detection plugin (plugin ID 303169) for the vulnerability, enabling automated scanning for affected systems (Tenable). No significant broader community controversy or threat actor attribution has been observed.

Additional resources


SourceThis report was generated using AI

Related IBM QRadar SIEM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-56462HIGH8.8
  • IBM QRadar SIEM logoIBM QRadar SIEM
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager
NoNoMay 27, 2026
CVE-2025-36051MEDIUM5.5
  • IBM QRadar SIEM logoIBM QRadar SIEM
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager
NoNoMar 19, 2026
CVE-2026-1276MEDIUM5.4
  • IBM QRadar SIEM logoIBM QRadar SIEM
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager
NoNoMar 19, 2026
CVE-2025-15051MEDIUM5.4
  • IBM QRadar SIEM logoIBM QRadar SIEM
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager
NoNoMar 19, 2026
CVE-2025-13995MEDIUM5
  • IBM QRadar SIEM logoIBM QRadar SIEM
  • cpe:2.3:a:ibm:qradar_security_information_and_event_manager
NoNoMar 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management