Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM encourages customers to update their systems promptly. IBM SOAR QRadar Plugin App 5.6.2
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25309 | IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7242664 |
|
Mon, 01 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:soar_qradar_plugin_app:*:*:*:*:*:*:*:* |
Wed, 20 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Title | IBM QRadar SOAR Plugin App path traversal | |
| First Time appeared |
Ibm
Ibm soar Qradar Plugin App |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:ibm:soar_qradar_plugin_app:1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:soar_qradar_plugin_app:5.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm soar Qradar Plugin App |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-20T14:56:15.871Z
Reserved: 2025-04-15T21:16:17.124Z
Link: CVE-2025-36114
Updated: 2025-08-20T14:56:08.543Z
Status : Analyzed
Published: 2025-08-20T15:15:32.460
Modified: 2025-12-01T17:54:27.440
Link: CVE-2025-36114
No data.
OpenCVE Enrichment
No data.
EUVD