CVE-2025-33118: IBM QRadar SIEM cross-site scripting
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33118?
CVE-2025-33118 has a critical severity rating, indicating a high risk for exploitation.
How do I fix CVE-2025-33118?
To fix CVE-2025-33118, upgrade IBM QRadar SIEM to a version after 7.5.0 Update Pack 12 that includes the necessary security patches.
What type of exploit is CVE-2025-33118 associated with?
CVE-2025-33118 is associated with stored cross-site scripting (XSS) vulnerabilities.
Who is affected by CVE-2025-33118?
CVE-2025-33118 affects users of IBM QRadar SIEM versions 7.5 through 7.5.0 Update Pack 12.
What potential impact does CVE-2025-33118 have?
The impact of CVE-2025-33118 includes altered functionality of the Web UI and potential disclosure of user credentials.