CVE-2019-4262: IBM Qradar Security Information And Event Manager

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.

Affected products

  • IBM Qradar Security Information And Event Manager: from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.3.0, before 7.3.2 (fixed in 7.3.2); version 7.2.8 only; version 7.3.2 only

Published 2019-09-26. Last modified 2026-06-17.