CVE-2024-45636Medium· 4.1▾ SunlitIBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.09%
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
security_qradar_edr >= 3.12, < 3.12.25Upgrade past the affected range:
security_qradar_edr 3.12.25Connected by shared product, vendor, weakness, or advisory.
CVE-2025-36335Medium· 6.2IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.
CVE-2026-84884High· 7.5IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format
CVE-2026-81208High· 7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials
CVE-2026-17643High· 8.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
CVE-2026-18124Medium· 6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.
CVE-2026-11921Critical· 9.1IBM Verify Identity Access containers may not apply management password change operations correctly.