
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36051 is an information disclosure vulnerability in IBM QRadar SIEM that allows local users to read sensitive data stored in configuration files. It affects IBM QRadar SIEM versions 7.5.0 through 7.5.0 Update Package 14. The vulnerability was published on March 19, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium), reflecting a local attack vector with high confidentiality impact but no integrity or availability impact (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory), meaning IBM QRadar SIEM improperly stores sensitive data — such as credentials, API keys, or database passwords — in configuration files that are readable by local, low-privileged users. Exploitation requires only local file system access with standard user privileges; no authentication bypass, special permissions, or user interaction is needed. An attacker with a local account on the QRadar system can simply read the affected configuration files to extract sensitive information (IBM Advisory, Feedly).
Successful exploitation exposes sensitive information stored in QRadar SIEM configuration files, potentially including credentials, API keys, and database passwords. Since QRadar SIEM is a security monitoring platform with broad access to network telemetry and integrated systems, credential exposure could enable lateral movement to connected infrastructure or allow an attacker to tamper with security monitoring capabilities. The impact is limited to confidentiality — there is no direct integrity or availability impact from this vulnerability alone (IBM Advisory).
/opt/qradar/ or similar QRadar installation paths).cat, less, grep) to extract sensitive information such as database passwords, API keys, or service credentials from the accessible configuration files./opt/qradar/conf/ or similar installation paths by non-administrative local users.auditd logs) for sensitive config file reads.cat, grep, strings) executed by non-privileged users targeting QRadar configuration directories.IBM has released a patch addressing this vulnerability; users should apply the update available at the IBM support page (node/7266709), which covers all affected versions from 7.5.0 through 7.5.0 Update Package 14. As interim mitigations, administrators should restrict file system permissions on QRadar configuration directories to limit read access to only necessary administrative accounts, enforce the principle of least privilege for local user accounts, and enable file access auditing to detect unauthorized reads of sensitive configuration files (IBM Advisory).
Heise (a German technology news outlet) covered the vulnerability, noting that SSH sessions in IBM QRadar SIEM could be compromised as a result of the exposed configuration data (Heise). Tenable published a Nessus detection plugin (plugin ID 303169) for the vulnerability, enabling automated scanning for affected systems (Tenable). No significant broader community controversy or threat actor attribution has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."