# CVE-2025-25022

## Summary

- **CVE ID:** CVE-2025-25022
- **Severity:** CRITICAL
- **CVSS Score:** 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-260
- **Published:** Jun 3, 2025
- **Last Modified:** Mar 12, 2026

## Description

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.

## Affected Products

- IBM — QRadar Suite Software (1.10.12.0)
- IBM — Cloud Pak for Security (1.10.0.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7235432)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._