LiveActive security incident?Get immediate response
CVE Record

CVE-2021-38869: IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede...

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

MediumCVSS 4.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

IBM QRadar SIEM may leave some users logged in after their configured idle timeout. In a security monitoring console, that can let someone with access to an unattended session continue using it. The issue is rated medium and appears limited by the physical-access CVSS vector.

Executive priority

Handle as a medium-priority hygiene issue for SIEM environments. It is not described as remotely exploitable, but QRadar has sensitive operational visibility, so lingering sessions can create avoidable insider or physical-access risk.

Technical view

CVE-2021-38869 affects IBM QRadar SIEM 7.3.3, 7.4.3, and 7.5.0. The source describes an idle-session timeout failure in some situations. CVSS 3.0 score is 4.3 with physical attack vector, low complexity, and low confidentiality, integrity, and availability impacts.

Likely exposure

Exposure is most relevant where QRadar consoles or administrator workstations can remain unlocked or shared. Internet-facing exposure is not supported by the supplied CVSS vector, which lists physical access as the attack vector.

Exploitation context

The bundle does not show CISA KEV listing or active exploitation. IBM X-Force lists exploit maturity as unproven through the provided CVSS temporal vector, so treat exploitation evidence as incomplete rather than confirmed.

Researcher notes

The public bundle gives limited technical detail and no CWE. The CVSS vector is unusual for a session timeout issue because it specifies physical access. Avoid assuming web-session takeover mechanics beyond IBM's statement that idle logout may fail in some situations.

Mitigation direction

  • Check IBM advisory 6574787 for the official fixed QRadar level.
  • Prioritize upgrades for affected QRadar 7.3.3, 7.4.3, and 7.5.0 deployments.
  • Enforce workstation locking and short screen-lock policies for QRadar users.
  • Limit physical and console access to QRadar administration workstations.
  • Review SIEM console access controls and administrator session policies.

Validation and detection

  • Inventory QRadar versions and compare against the affected versions listed by IBM/CVE.
  • Confirm idle timeout behavior in a controlled, authorized test session.
  • Check whether IBM's advisory identifies your installed build as fixed or vulnerable.
  • Review access logs for sessions continuing after expected inactivity timeout.
  • Verify compensating workstation lock controls on QRadar operator endpoints.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-38869 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
4.3 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
4.3CVSS 3.0MediumCVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O0.93.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

4.3Medium
CVSS 3.0 vector shape for CVE-2021-38869Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/C:L/AC:L/AV:P/I:L/PR:N/S:U/A:L/UI:N/RC:C/E:U/RL:O

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMQRadar SIEM7.3.3, 7.4.3, 7.5.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.