Security readout for executives and security teams
Plain-English summary
IBM QRadar SIEM may leave some users logged in after their configured idle timeout. In a security monitoring console, that can let someone with access to an unattended session continue using it. The issue is rated medium and appears limited by the physical-access CVSS vector.
Executive priority
Handle as a medium-priority hygiene issue for SIEM environments. It is not described as remotely exploitable, but QRadar has sensitive operational visibility, so lingering sessions can create avoidable insider or physical-access risk.
Technical view
CVE-2021-38869 affects IBM QRadar SIEM 7.3.3, 7.4.3, and 7.5.0. The source describes an idle-session timeout failure in some situations. CVSS 3.0 score is 4.3 with physical attack vector, low complexity, and low confidentiality, integrity, and availability impacts.
Likely exposure
Exposure is most relevant where QRadar consoles or administrator workstations can remain unlocked or shared. Internet-facing exposure is not supported by the supplied CVSS vector, which lists physical access as the attack vector.
Exploitation context
The bundle does not show CISA KEV listing or active exploitation. IBM X-Force lists exploit maturity as unproven through the provided CVSS temporal vector, so treat exploitation evidence as incomplete rather than confirmed.
Researcher notes
The public bundle gives limited technical detail and no CWE. The CVSS vector is unusual for a session timeout issue because it specifies physical access. Avoid assuming web-session takeover mechanics beyond IBM's statement that idle logout may fail in some situations.
Mitigation direction
- Check IBM advisory 6574787 for the official fixed QRadar level.
- Prioritize upgrades for affected QRadar 7.3.3, 7.4.3, and 7.5.0 deployments.
- Enforce workstation locking and short screen-lock policies for QRadar users.
- Limit physical and console access to QRadar administration workstations.
- Review SIEM console access controls and administrator session policies.
Validation and detection
- Inventory QRadar versions and compare against the affected versions listed by IBM/CVE.
- Confirm idle timeout behavior in a controlled, authorized test session.
- Check whether IBM's advisory identifies your installed build as fixed or vulnerable.
- Review access logs for sessions continuing after expected inactivity timeout.
- Verify compensating workstation lock controls on QRadar operator endpoints.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-38869 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 4.3 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O0.93.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
4.3MediumVector: CVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ibm.com/support/pages/node/6574787CVE reference · x_refsource_CONFIRM
- ibm-qradar-cve202138869-session-fixation (208341)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
