IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
CVE ID: CVE-2025-25022
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.6
CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor: IBM
Product: QRadar Suite Software, Cloud Pak for Security
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 7.91% (scored less or equal to compared to others)
EPSS Date: 2025-06-04 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false