CVE-2025-36376: IBM Security QRadar EDR Software has multiple vulnerabilities
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Security ReaQta does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36376?
CVE-2025-36376 is classified as a medium severity vulnerability due to its potential to allow session impersonation.
How do I fix CVE-2025-36376?
To remediate CVE-2025-36376, upgrade IBM Security QRadar EDR to version 3.12.24 or later.
What are the implications of CVE-2025-36376?
CVE-2025-36376 could allow a malicious authenticated user to impersonate another user and access sensitive information.
Which versions of IBM Security QRadar EDR are affected by CVE-2025-36376?
IBM Security QRadar EDR versions from 3.12 to 3.12.23 are affected by CVE-2025-36376.
Is user authentication at risk in CVE-2025-36376?
Yes, CVE-2025-36376 impacts user authentication by not invalidating sessions after expiration, increasing the risk of impersonation.