
CVE-2025-36376 IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another use… https://www.cve.org/CVERecord?id=CVE-2025-36376
Post summary
IBM Security QRadar EDR 3.12 through 3.12.23 suffers a session invalidation flaw that can let an authenticated user impersonate another user.

