Article Details
Scrape Timestamp (UTC): 2025-06-05 02:35:29.880
Source: https://www.theregister.com/2025/06/05/ibm_cloud_outage_critical_vulnerability/
Original Article Text
Click to Toggle View
IBM Cloud login breaks for second time this week and Big Blue isn't saying why. To make matters worse, IBM's security software has a critical vuln caused by exposed password. IBM isn’t having its best week after the company experienced another cloudy outage and a critical-rated vulnerability. The outage repeated the Tuesday incident that saw users unable to access the console through which they manage their cloudy resources, or to open and view support cases. Big Blue’s cloud displayed similar symptoms on May 21. We’ve asked IBM if the incidents are related, but the company has not responded at the time of writing. The Wednesday authentication outage started at 9:03 AM UTC and ended over four hours later at 1:20 PM UTC. IBM’s status page offers no information about the cause. Messages sent to customers urge them to “perform health checks of their resources, and contact IBM Cloud Support if they continue to experience failures.” However, if the problem recurs it will likely again mean customers cannot open or view support cases, meaning IBM support may not be able to offer much help! IBM Japan offered “sincere apologies to all concerned parties for the inconvenience caused.” Also on Wednesday, IBM issued a security bulletin that reveals its QRadar threat detection and response tools, and Cloud Pak for Security integration suite, both left a password in a configuration file. Bug-assessors scored the resulting CVE-2025-2502 9.6 on the ten-point Common Vulnerability Scoring System, meaning it is considered a critical vulnerability. IBM’s security bulletin also advised of four other QRadar flaws, rated 7.2, 6.5, 4.8 and 4.0. The good news is that IBM introduced the flaws in recent double-point upgrades to its products, so perhaps many users haven’t installed the vulnerable products. Those who have may now face an extra chore, unless compensating controls are in place to eliminate the need for a rushed patch.
Daily Brief Summary
IBM encountered a repeated outage impacting user access to its cloud management console, similar to an incident earlier in the week.
The outage prevented users from managing cloud resources and viewing support cases, starting at 9:03 AM UTC and resolving by 1:20 PM UTC.
IBM has not disclosed the cause of the outage, leaving customers with limited guidance on resolution and preventive measures.
A critical vulnerability was also reported in IBM's security software, where a password was left exposed in a configuration file.
The vulnerability, rated 9.6/10, affects IBM's QRadar and Cloud Pak for Security, posing a significant security risk to users.
IBM issued advisories for additional QRadar vulnerabilities with varied severity ranging from moderate to high.
Despite the severity, the flagged vulnerabilities were introduced in recent product updates, potentially limiting the number of affected users.
Customers who have implemented the updates are advised to establish compensating controls or prepare for urgent patching efforts.