Show filters
196 Total Results
Displaying 111-120 of 196
Sort by:
Attacker Value
Unknown

CVE-2020-4165

Disclosure Date: August 24, 2020 (last updated February 22, 2025)
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174401.
Attacker Value
Unknown

CVE-2020-4186

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174804.
Attacker Value
Unknown

CVE-2020-4185

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803.
Attacker Value
Unknown

CVE-2020-4173

Disclosure Date: July 08, 2020 (last updated February 21, 2025)
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 174682.
Attacker Value
Unknown

CVE-2020-4188

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
Attacker Value
Unknown

CVE-2020-4191

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852.
Attacker Value
Unknown

CVE-2020-4183

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.
Attacker Value
Unknown

CVE-2020-4193

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
Attacker Value
Unknown

CVE-2020-4307

Disclosure Date: June 02, 2020 (last updated November 27, 2024)
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM X-Force ID: 176997.
Attacker Value
Unknown

CVE-2020-4190

Disclosure Date: June 02, 2020 (last updated February 21, 2025)
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174851.