Skip to main content

Vendor/product archive

ibm / security_qradar_edr CVEs

Beta · best-effort

15 CVEs tagged to ibm / security_qradar_edr0 Critical, 0 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2025-36376

Published Feb 17, 2026

IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the syst…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-35006

Published Jul 10, 2024

IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33860

Published Jul 10, 2024

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33859

Published Jul 10, 2024

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1