IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
PUBLISHED5.2ApplicationCWE-613
IBM Security QRadar EDR Software has multiple vulnerabilities
Problem type
Affected products
IBM
Security QRadar EDR
<= 3.12.23 - AFFECTED
References
GitHub Security Advisories
GHSA-cxcr-rj95-h6f4
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session...
https://github.com/advisories/GHSA-cxcr-rj95-h6f4IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2025-36376Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-36376",
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"dateUpdated": "2026-02-17T20:41:36.549Z",
"dateReserved": "2025-04-15T21:16:56.325Z",
"datePublished": "2026-02-17T20:37:28.659Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm",
"dateUpdated": "2026-02-17T20:41:36.549Z"
},
"title": "IBM Security QRadar EDR Software has multiple vulnerabilities",
"descriptions": [
{
"lang": "en",
"value": "IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.</p>"
}
]
}
],
"affected": [
{
"vendor": "IBM",
"product": "Security QRadar EDR",
"cpes": [
"cpe:2.3:a:ibm:security_qradar_edr:3.12:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:security_qradar_edr:3.12.23:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "3.12",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "3.12.23"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-613 Insufficient Session Expiration",
"cweId": "CWE-613",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7260390",
"tags": [
"vendor-advisory",
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
}
],
"solutions": [
{
"lang": "en",
"value": "IBM encourages customers to update their systems promptly.\n\nProductFix versionIBM Security QRadar EDR3.12.24\n\n \n\nThe IBM Security QRadar EDR operator can be upgraded automatically when new compatible versions are available. However, you can control whether an operator is upgraded automatically by setting an approval strategy.\n\nTwo approval strategies are available:\n\n * Automatic (default) - New operator versions are installed automatically when they are available on the subscription channel.\n * Manual - When a new operator version is available on the subscription channel, the subscription indicates that an update is available, but you must approve the update manually.\n\n\nFor more information about the manual installation process, view Installing QRadar EDR https://www.ibm.com/docs/en/security-qradar-edr/3.12",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM encourages customers to update their systems promptly.</p><div><table><tbody><tr><td>Product</td><td>Fix version</td></tr><tr><td>IBM Security QRadar EDR</td><td>3.12.24</td></tr></tbody></table></div><p> </p><p>The IBM Security QRadar EDR operator can be upgraded automatically when new compatible versions are available. However, you can control whether an operator is upgraded automatically by setting an approval strategy.</p><div><p>Two approval strategies are available:</p><ul><li>Automatic (default) - New operator versions are installed automatically when they are available on the subscription channel.</li><li>Manual - When a new operator version is available on the subscription channel, the subscription indicates that an update is available, but you must approve the update manually.</li></ul><p>For more information about the manual installation process, view <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.ibm.com/docs/en/security-qradar-edr/3.12?topic=overview-whats-new-changed\">Installing QRadar EDR</a></p></div><br>"
}
]
}
]
}
}
}