CVE-2025-25023Incorrect Privilege Assignment in IBM Security Guardium

Severity
4.9MEDIUMNVD
EPSS
0.2%
top 59.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9

Description

IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/security_guardium11.412.1
CVEListV5ibm/security_guardium11.4, 12.1

🔴Vulnerability Details

2
CVEList
IBM Security Guardium information disclosure2025-04-09
GHSA
GHSA-223p-m2w6-92v2: IBM Security Guardium 112025-04-09
CVE-2025-25023 — Incorrect Privilege Assignment in IBM | cvebase