Show filters
196 Total Results
Displaying 131-140 of 196
Sort by:
Attacker Value
Unknown

CVE-2019-4306

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.
Attacker Value
Unknown

CVE-2019-4330

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.
Attacker Value
Unknown

CVE-2019-4422

Disclosure Date: October 01, 2019 (last updated November 27, 2024)
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.
Attacker Value
Unknown

CVE-2019-4338

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced by an actor. This weakness can be used to consume more resources than intended. IBM X-Force ID: 161417.
Attacker Value
Unknown

CVE-2019-4340

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 161419.
Attacker Value
Unknown

CVE-2019-4310

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.
Attacker Value
Unknown

CVE-2019-4292

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698.
Attacker Value
Unknown

CVE-2018-1889

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.
0
Attacker Value
Unknown

CVE-2017-1597

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
0
Attacker Value
Unknown

CVE-2018-1891

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.
0