IBM QRadar SIEM
cpe:2.3:a:ibm:qradar_security_information_and_event_manager:*:*:*:*:*:*:*
- >= 7.5, <= 7.5.0 UP12 IF01
An XML external entity injection (XXE) vulnerability has been identified in IBM QRadar SIEM versions 7.5 through 7.5.0 Update Package 12. This vulnerability arises when the application processes XML data, allowing remote attackers to exploit it to access sensitive information or deplete memory resources.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information or excessive memory consumption, potentially causing a denial-of-service condition.
Users are advised to update to IBM QRadar SIEM version 7.5.0 Update Package 12 Interim Fix 02.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.