Show filters
196 Total Results
Displaying 61-70 of 196
Sort by:
Attacker Value
Unknown

CVE-2021-29735

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2020-4690

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.
Attacker Value
Unknown

CVE-2021-20377

Disclosure Date: September 21, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.
Attacker Value
Unknown

CVE-2021-29773

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.
Attacker Value
Unknown

CVE-2021-20433

Disclosure Date: September 14, 2021 (last updated November 28, 2024)
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.
Attacker Value
Unknown

CVE-2021-20418

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
Attacker Value
Unknown

CVE-2021-20427

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
Attacker Value
Unknown

CVE-2021-20420

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.
Attacker Value
Unknown

CVE-2020-4990

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
Attacker Value
Unknown

CVE-2021-20386

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.