CVE-2025-33141 Overview
CVE-2025-33141 is an information disclosure vulnerability in IBM QRadar Security Information and Event Management (SIEM). The flaw affects IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006. Authenticated users can read sensitive information from backup files because of incorrect permissions assignment [CWE-497]. Because QRadar backups often contain configuration data, credentials, and historical event data, unauthorized access to these files can expose material used for further attacks against the SIEM environment or downstream systems it monitors.
Critical Impact
An authenticated low-privilege user can retrieve sensitive data stored in QRadar backup files, potentially exposing configuration, credentials, or event data collected by the SIEM.
Affected Products
- IBM QRadar SIEM 7.5.0
- IBM QRadar SIEM 7.5.0 versions up to and including UP15 Interim Fix 006
- Deployments retaining backup artifacts on affected QRadar hosts
Discovery Timeline
- 2026-09-18 - CVE-2025-33141 published to the National Vulnerability Database
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2025-33141
Vulnerability Analysis
The vulnerability is classified under [CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere]. IBM QRadar writes backup archives to disk with permissions that are broader than required for the backup workflow. An authenticated user with access to the QRadar host, but without administrative rights over the backup subsystem, can open or copy these files. The exposed content depends on which backup type was performed. Configuration backups typically include appliance settings, tuning parameters, references to integrated data sources, and material used to reconstruct the deployment. Data backups may include event and flow records collected by the SIEM. The confidentiality impact is high, while integrity and availability of the system are not affected.
Root Cause
The root cause is an incorrect permissions assignment on backup files generated by QRadar. Files are created without applying least-privilege access controls, allowing accounts that should not be able to read backup content to do so. The issue is a local access control weakness exposed to any authenticated principal that reaches the storage location.
Attack Vector
Exploitation requires an authenticated session against an affected QRadar deployment. The attacker locates backup archives on the appliance and reads them directly using standard file access tools. No user interaction, memory corruption primitive, or additional privilege escalation is required to complete the disclosure. Once retrieved, backup content can be extracted offline to harvest credentials, configuration secrets, or captured event data that supports lateral movement and evasion of the SIEM. See the IBM Support Documentation for vendor guidance.
No public proof-of-concept or exploitation in the wild has been reported for CVE-2025-33141.
Detection Methods for CVE-2025-33141
Indicators of Compromise
- Read access to files under the QRadar backup directory by non-administrative accounts.
- Unexpected copy, scp, or archive extraction operations targeting .tgz or .tar.gz backup artifacts on QRadar hosts.
- QRadar audit log entries showing backup file downloads outside of scheduled administrative activity.
Detection Strategies
- Audit file system permissions on QRadar backup directories and flag files that are world-readable or group-readable by non-privileged accounts.
- Correlate authentication events with subsequent file access on the QRadar appliance to identify low-privilege users touching backup storage.
- Compare installed QRadar version against 7.5.0 UP15 Interim Fix 006 and flag hosts at or below that patch level.
Monitoring Recommendations
- Enable file integrity monitoring on QRadar backup directories and alert on read operations by unexpected users or processes.
- Ingest QRadar operating system logs into a SIEM or data lake and build detections for anomalous access patterns to backup paths.
- Review privileged access reports for accounts that have shell access to QRadar hosts but no operational need for backup data.
How to Mitigate CVE-2025-33141
Immediate Actions Required
- Apply the IBM-provided fix that supersedes QRadar 7.5.0 UP15 Interim Fix 006 as documented in the vendor advisory.
- Restrict shell and console access on QRadar hosts to administrators who require it for operational duties.
- Rotate credentials and secrets contained in any backup archive that could have been accessed by unauthorized users.
Patch Information
IBM has published remediation guidance in the IBM Support Documentation. Administrators should upgrade beyond IBM QRadar 7.5.0 UP15 Interim Fix 006 to the fixed release identified by IBM. Confirm patch application by validating the QRadar version and reviewing backup file permissions after the update.
Workarounds
- Move existing backup archives to storage that is only accessible to the QRadar administrator account and adjust permissions to remove read access for other users.
- Encrypt backup archives at rest so that file-level read access does not directly yield plaintext content.
- Limit the retention window for backups on the appliance and offload them to a secured remote store as soon as they are created.
# Example: restrict permissions on existing QRadar backup files
chown root:root /store/backup/*.tgz
chmod 600 /store/backup/*.tgz
# Verify no non-privileged users can read backup archives
ls -l /store/backup/
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.