IBM QRadar Suite Software and Cloud Pak for Security Code Execution Vulnerability

Vulnerability

A code execution vulnerability has been identified in IBM QRadar Suite Software versions 1.10.12.0 through 1.11.2.0, as well as in IBM Cloud Pak for Security versions 1.10.0.0 through 1.10.11.0. This vulnerability arises from improper code generation, which could allow a privileged user to execute code during case management script creation.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution within the application.

Remediation

Users are advised to upgrade to version 1.11.3.0 or later. Instructions for upgrading can be found in the IBM Cloud Pak for Security documentation.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.