CVE-2025-36377: IBM Security QRadar EDR Software has multiple vulnerabilities
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
Other sources
IBM Security ReaQta does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36377?
CVE-2025-36377 has a medium severity rating due to its potential for user impersonation.
How do I fix CVE-2025-36377?
To fix CVE-2025-36377, upgrade IBM Security QRadar EDR to version 3.12.24 or later.
What vulnerabilities are associated with CVE-2025-36377?
CVE-2025-36377 is associated with session management vulnerabilities that can lead to user impersonation.
Who is affected by CVE-2025-36377?
IBM Security QRadar EDR versions 3.12 through 3.12.23 are affected by CVE-2025-36377.
What should organizations do regarding CVE-2025-36377?
Organizations should assess their use of affected versions of IBM Security QRadar EDR and apply the necessary updates to mitigate the vulnerability.