CVE-2025-25019: IBM Cloud Pak For Security

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.

Affected products

  • IBM Cloud Pak For Security: from 1.10.0.0, up to and including 1.10.11.0
  • IBM Qradar Suite: from 1.10.12.0, up to and including 1.11.2.0

Published 2025-06-03. Last modified 2026-06-17.