Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-49336

Disclosure Date: December 19, 2024 (last updated January 13, 2025)
IBM Security Guardium 11.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Attacker Value
Unknown

CVE-2023-47710

Disclosure Date: May 24, 2024 (last updated January 12, 2025)
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525.
Attacker Value
Unknown

CVE-2023-47712

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
0
Attacker Value
Unknown

CVE-2023-47711

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
Attacker Value
Unknown

CVE-2023-47709

Disclosure Date: May 14, 2024 (last updated January 15, 2025)
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
Attacker Value
Unknown

CVE-2023-42004

Disclosure Date: November 28, 2023 (last updated December 05, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
Attacker Value
Unknown

CVE-2022-43906

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.
Attacker Value
Unknown

CVE-2023-30437

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
Attacker Value
Unknown

CVE-2023-30436

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.
Attacker Value
Unknown

CVE-2023-30435

Disclosure Date: August 27, 2023 (last updated October 08, 2023)
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.