Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2021-20428

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.
Attacker Value
Unknown

CVE-2021-20426

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.
Attacker Value
Unknown

CVE-2021-20389

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
Attacker Value
Unknown

CVE-2020-4184

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..
Attacker Value
Unknown

CVE-2020-4952

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028.
Attacker Value
Unknown

CVE-2020-4189

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850.
Attacker Value
Unknown

CVE-2020-4921

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.
Attacker Value
Unknown

CVE-2020-4688

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
Attacker Value
Unknown

CVE-2020-4678

Disclosure Date: October 09, 2020 (last updated November 28, 2024)
IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to. IBM X-Force ID: 186423.
Attacker Value
Unknown

CVE-2020-4689

Disclosure Date: October 09, 2020 (last updated February 22, 2025)
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.