CVE-2023-30437

3 documents3 sources
Severity
5.3MEDIUM
EPSS
0.1%
top 71.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 27
Latest updateAug 28

Description

IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/security_guardium11.3, 11.4, 11.5
NVDibm/security_guardium11.3, 11.4, 11.5+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-69hj-qg9v-rx7w: IBM Security Guardium 112023-08-28
CVEList
IBM Security Guardium information disclosure2023-08-27
CVE-2023-30437 (MEDIUM CVSS 5.3) | IBM Security Guardium 11.3 | cvebase.io