Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly encourages customers to update their systems promptly. Please upgrade to at least version 1.11.3.0 according to the following instructions: https://www.ibm.com/docs/en/cloud-paks/cp-security/1.11?topic=installing https://www.ibm.com/docs/en/cloud-paks/cp-security/1.11?topic=upgrading
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16757 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7235432 |
|
Tue, 12 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:*:*:*:*:*:*:*:* |
Tue, 03 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. | |
| Title | IBM QRadar Suite Software and IBM Cloud Pak for Security session fixation | |
| First Time appeared |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_for_security:1.10.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_for_security:1.10.11.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.10.12.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qradar_suite:1.11.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cloud Pak For Security Ibm qradar Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T12:00:16.388Z
Reserved: 2025-01-31T16:26:45.223Z
Link: CVE-2025-25019
Updated: 2025-06-03T15:37:44.631Z
Status : Analyzed
Published: 2025-06-03T16:15:23.960
Modified: 2025-08-12T20:03:09.690
Link: CVE-2025-25019
No data.
OpenCVE Enrichment
No data.
EUVD