CVE-2025-0164
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-14

Last updated on: 2025-12-15

Assigner: IBM Corporation

Description
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-14
Last Modified
2025-12-15
Generated
2026-05-07
AI Q&A
2025-09-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 15 associated CPEs
Vendor Product Version / Range
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
ibm qradar_security_information_and_event_manager 7.5.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

The impact is limited to local privileged users being able to perform unauthorized actions on configuration files, potentially leading to limited confidentiality exposure. There is no impact on integrity or availability. The attack requires high privileges and no user interaction. [1]


What immediate steps should I take to mitigate this vulnerability?

The immediate step to mitigate this vulnerability is to promptly update IBM QRadar SIEM to version 7.5.0 UP13 IF02, where the issue has been fixed. No workarounds or other mitigations are available. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

There are no specific detection commands or network detection methods provided for this vulnerability. Detection would likely involve verifying the permission settings on critical configuration files in IBM QRadar SIEM versions 7.5 through 7.5.0 UP13 IF01 to identify improper permission assignments, but no explicit commands or tools are suggested. [1]


Can you explain this vulnerability to me?

This vulnerability in IBM QRadar SIEM versions 7.5 through 7.5.0 UP13 IF01 involves improper permission assignment on critical configuration files. It allows a local privileged user to perform unauthorized actions on these configuration files due to incorrect permission settings. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart