CVE-2014-6075: IBM Qradar Risk Manager

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

Affected products

  • IBM Qradar Risk Manager: version 7.1.0 only; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only; version 7.2.3 only; version 7.2.4 only
  • IBM Qradar Security Information And Event Manager: version 7.1.0 only; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only; version 7.2.3 only; version 7.2.4 only
  • IBM Qradar Vulnerability Manager: version 7.2.0 only; version 7.2.1 only; version 7.2.2 only; version 7.2.3 only; version 7.2.4 only

Published 2014-11-28. Last modified 2026-06-17.