CVE-2025-36377: IBM Qradar Edr

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.

Affected products

  • IBM Qradar Edr: from 3.12.0, before 3.12.24 (fixed in 3.12.24)

Published 2026-02-17. Last modified 2026-06-17.