CVE Vulnerabilities

CVE-2025-33119

Password in Configuration File

Published: Nov 12, 2025 | Modified: Dec 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

Weakness

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

Affected Software

NameVendorStart VersionEnd Version
Qradar_security_information_and_event_managerIbm7.5.0 (including)7.5.0 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_1 (including)7.5.0-update_pack_1 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_10 (including)7.5.0-update_pack_10 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_11 (including)7.5.0-update_pack_11 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_12 (including)7.5.0-update_pack_12 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_13 (including)7.5.0-update_pack_13 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_13_interim_fix_01 (including)7.5.0-update_pack_13_interim_fix_01 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_13_interim_fix_02 (including)7.5.0-update_pack_13_interim_fix_02 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_14 (including)7.5.0-update_pack_14 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_2 (including)7.5.0-update_pack_2 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_3 (including)7.5.0-update_pack_3 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_4 (including)7.5.0-update_pack_4 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_5 (including)7.5.0-update_pack_5 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_6 (including)7.5.0-update_pack_6 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_7 (including)7.5.0-update_pack_7 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_8 (including)7.5.0-update_pack_8 (including)
Qradar_security_information_and_event_managerIbm7.5.0-update_pack_9 (including)7.5.0-update_pack_9 (including)

Potential Mitigations

References