IBMCVE-2025-33141
IBM QRadar: information disclosure
Medium6.5CVE-2025-33141 · Published Sep 18, 2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| QRadar Product | >= 7.5.0, <= 7.5.0 UP15 Interim Fix 006 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-497
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | IBM Guardium Data Protection: improper authorization | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: cross-site request forgery | High8.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: command injection | High8.1 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: remote code execution | High7.2 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: privilege escalation | High7.8 | No fix yet |
| Sep 18 | IBM Guardium Data Protection: information disclosure | High7.7 | No fix yet |