← Back

CVE-2026-10025

nvd nist
Published: Aug 5, 2026Modified: Aug 10, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

Affected (26)

1 product
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.5.0
Version 7.5.0 update_pack_10
Version 7.5.0 update_pack_11
Version 7.5.0 update_pack_12
Version 7.5.0 update_pack_13
Version 7.5.0 update_pack_13_interim_fix_01
Version 7.5.0 update_pack_13_interim_fix_02
Version 7.5.0 update_pack_14
Version 7.5.0 update_pack_14_interim_fix_01
Version 7.5.0 update_pack_14_interim_fix_02
Version 7.5.0 update_pack_15
Version 7.5.0 update_pack_15_interim_fix_01
Version 7.5.0 update_pack_15_interim_fix_02
Version 7.5.0 update_pack_15_interim_fix_03
Version 7.5.0 update_pack_15_interim_fix_04
Version 7.5.0 update_pack_1
Version 7.5.0 update_pack_2
Version 7.5.0 update_pack_3
Version 7.5.0 update_pack_4
Version 7.5.0 update_pack_5
Version 7.5.0 update_pack_6
Version 7.5.0 update_pack_7
Version 7.5.0 update_pack_8
Version 7.5.0 update_pack_9
Version 7.6.0
Version 7.6.0 fix_pack_1

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.