Information Disclosure Vulnerability in IBM QRadar SIEM
A vulnerability in IBM QRadar SIEM allows a remote, authenticated attacker to gain unauthorized access to sensitive information.
CVE search metadata
CVE search record: CVE-2024-42037. Severity: critical. CVSS: 9.3. EPSS: 0.12%. KEV: no. Product: QRadar SIEM. Brief: Information Disclosure Vulnerability in IBM QRadar SIEM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-qradar-disclosure/
IBM has disclosed a security vulnerability identified as CVE-2024-42037 affecting IBM QRadar SIEM. The vulnerability permits a remote, authenticated attacker to access sensitive information that should otherwise be restricted. Successful exploitation of this flaw leads to unauthorized information disclosure, potentially exposing configuration details, logs, or system data. This issue highlights the importance of access control verification within the SIEM environment. As of the current advisory, there are no reports of widespread active exploitation, but the impact necessitates prompt patch management to prevent potential reconnaissance activities by authorized users who may attempt to exceed their privileges.
Impact
The vulnerability allows an authenticated user to bypass intended access controls to retrieve restricted system data. Successful exploitation could compromise the confidentiality of security data managed by the SIEM, affecting organizations that rely on QRadar for sensitive log aggregation and incident response. The scope of impact is limited to organizations using vulnerable versions of IBM QRadar SIEM.
Recommendation
Prioritize patching of the affected IBM QRadar SIEM instances as specified by the vendor's security bulletin. Monitor access logs for unusual patterns of data retrieval or high volumes of unexpected queries originating from authenticated user accounts.
Immediate actions
Review vendor security bulletin and apply available security patches for IBM QRadar SIEM.
Threat Hunt
Authenticated users performing unusually high volumes of administrative information queries.
Data: QRadar system access logs
Mitigations
Patch IBM QRadar SIEM software.
CVE-2024-42037