IBM QRadar Suite Software and Cloud Pak for Security Session Management Vulnerability Allowing User Impersonation

Vulnerability

A vulnerability exists in IBM QRadar Suite Software versions 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0. These versions do not properly invalidate user sessions after logout, potentially allowing a user to impersonate another user on the system.

Impact

Exploitation of this vulnerability could lead to unauthorized user impersonation.

Remediation

Users are advised to upgrade to version 1.11.3.0 or later. Instructions for upgrading can be found in the IBM Cloud Pak for Security documentation.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.