Show filters
196 Total Results
Displaying 11-20 of 196
Sort by:
Attacker Value
Unknown

CVE-2023-47711

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
Attacker Value
Unknown

CVE-2023-47709

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
Attacker Value
Unknown

CVE-2023-25926

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 247599.
Attacker Value
Unknown

CVE-2023-25921

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
Attacker Value
Unknown

CVE-2023-25925

Disclosure Date: February 28, 2024 (last updated December 18, 2024)
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.
Attacker Value
Unknown

CVE-2023-25922

Disclosure Date: February 28, 2024 (last updated December 18, 2024)
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
Attacker Value
Unknown

CVE-2023-47707

Disclosure Date: December 20, 2023 (last updated December 22, 2023)
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
Attacker Value
Unknown

CVE-2023-47705

Disclosure Date: December 20, 2023 (last updated December 22, 2023)
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
Attacker Value
Unknown

CVE-2023-47703

Disclosure Date: December 20, 2023 (last updated December 22, 2023)
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.
Attacker Value
Unknown

CVE-2023-47702

Disclosure Date: December 20, 2023 (last updated December 22, 2023)
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.