Executive brief
IBM Security QRadar EDR, a platform used for detecting and responding to cyber threats on endpoints, contains a vulnerability where user credentials are stored in an unencrypted format. This could allow a person who already has high-level administrative access to the local system to discover and steal these credentials. While the risk is mitigated by the requirement for existing high-level access, it could lead to further unauthorized access or lateral movement within an organization's network.
Technical details
IBM Security QRadar EDR (formerly ReaQta) versions 3.12 through 3.12.24 are vulnerable to plaintext storage of passwords (CWE-256). The vulnerability allows a local attacker with high privileges (PR:H) to read sensitive user credentials directly from storage because they are not properly encrypted or hashed. Exploitation is considered high complexity (AC:H) as it requires local access and specific administrative rights to reach the storage location. Successful exploitation results in a loss of confidentiality but does not directly impact system integrity or availability. The issue is resolved in version 3.12.25.
Affected products
- IBM Security QRadar EDR 3.12 through 3.12.24
Timeline
- 2026-06-02: disclosed: Initial publication by IBM
- 2026-06-02: patched: Fixed in version 3.12.25
- 2026-06-11: advisory: NVD publication date