Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2021-29735
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2021-20418
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
0
Attacker Value
Unknown
CVE-2021-20427
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
0
Attacker Value
Unknown
CVE-2021-20420
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.
0
Attacker Value
Unknown
CVE-2020-4990
Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
0
Attacker Value
Unknown
CVE-2021-20386
Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.
0
Attacker Value
Unknown
CVE-2021-20419
Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
0
Attacker Value
Unknown
CVE-2021-20385
Disclosure Date: May 21, 2021 (last updated November 28, 2024)
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.
0
Attacker Value
Unknown
CVE-2021-20557
Disclosure Date: May 21, 2021 (last updated February 22, 2025)
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
0