logo

IBM QRadar SIEM Vulnerability Allows Remote Command Execution

ID: e61dd464-8e9d-5bab-9d55-3a1be0c5c9ab

STIX ID: report--e61dd464-8e9d-5bab-9d55-3a1be0c5c9ab

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-06-20

Date Updated: 2026-04-13

Author: AnuPriya

...
...

IBM released a critical security bulletin for QRadar SIEM (7.5 → 7.5.0 UP12 IF01) disclosing three vulnerabilities—most notably CVE-2025-33117 (CVSS 9.1) enabling arbitrary command execution via a malicious autoupdate file, and CVE-2025-33121 (XXE) allowing data exposure—affecting all deployments on those versions; IBM published QRadar 7.5.0 UP12 Interim Fix 02 (SFS 20250610184357) and advises immediate patching, backups before upgrade, and monitoring of privileged account activity since no viable workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.