Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2020-4173
Disclosure Date: July 08, 2020 (last updated February 21, 2025)
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 174682.
0
Attacker Value
Unknown
CVE-2020-4188
Disclosure Date: June 22, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
0
Attacker Value
Unknown
CVE-2020-4190
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174851.
0
Attacker Value
Unknown
CVE-2019-4422
Disclosure Date: October 01, 2019 (last updated November 27, 2024)
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.
0