Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Very High

CVE-2014-6271

Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Attacker Value
Unknown

CVE-2023-47712

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
0
Attacker Value
Unknown

CVE-2023-47711

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
Attacker Value
Unknown

CVE-2023-47709

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
Attacker Value
Unknown

CVE-2023-42004

Disclosure Date: November 28, 2023 (last updated December 05, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
Attacker Value
Unknown

CVE-2022-43903

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
Attacker Value
Unknown

CVE-2022-43904

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
Attacker Value
Unknown

CVE-2023-30437

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
Attacker Value
Unknown

CVE-2023-30436

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.
Attacker Value
Unknown

CVE-2023-30435

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.