cbcvebase.

Ibm Security Guardium vulnerabilities

114 known vulnerabilities affecting ibm/security_guardium.

Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM60LOW5

Vulnerabilities

Page 1 of 6
CVE-2017-1253P2CRITICALCVSS 9.9v10.0v10.0.1+2 more2017-07-05
CVE-2017-1253 [CRITICAL] CWE-78 CVE-2017-1253: IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.
nvd
CVE-2020-4180P2HIGHCVSS 8.8v11.12020-06-03
CVE-2020-4180 [HIGH] CWE-78 CVE-2020-4180: IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.
nvd
CVE-2019-4292P3HIGHCVSS 8.8v10.52019-07-02
CVE-2019-4292 [HIGH] CWE-434 CVE-2019-4292: IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allo IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698.
nvd
CVE-2023-47709P3HIGHCVSS 8.8v11.3v11.4+3 more2024-05-14
CVE-2023-47709 [HIGH] CWE-78 CVE-2023-47709: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to exec IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
nvd
CVE-2017-1269P3CRITICALCVSS 9.8v10.0v10.0.1+2 more2017-07-05
CVE-2017-1269 [CRITICAL] CWE-89 CVE-2017-1269: IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send spe IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744
nvd
CVE-2023-35893P3HIGHCVSS 8.8v10.6v11.3+3 more2023-08-16
CVE-2023-35893 [HIGH] CWE-78 CVE-2023-35893: IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to exec IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824.
nvd
CVE-2022-43907P3HIGHCVSS 8.8v11.42023-08-27
CVE-2022-43907 [HIGH] CWE-78 CVE-2022-43907: IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.
nvd
CVE-2020-4952P3HIGHCVSS 8.8v11.22021-01-27
CVE-2020-4952 [HIGH] CVE-2020-4952: IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper acc IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028.
nvd
CVE-2017-1757P3HIGHCVSS 8.8v10.0v10.0.1+4 more2017-12-20
CVE-2017-1757 [HIGH] CWE-89 CVE-2017-1757: IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-cr IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.
nvd
CVE-2020-4921P3HIGHCVSS 8.8v10.6v11.22021-01-20
CVE-2020-4921 [HIGH] CWE-89 CVE-2020-4921: IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send spe IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.
nvd
CVE-2020-4990P3HIGHCVSS 8.8v11.22021-05-24
CVE-2020-4990 [HIGH] CWE-89 CVE-2020-4990: IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially cr IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
nvd
CVE-2016-0249P3HIGHCVSS 8.6≤ 8.2v9.0+5 more2016-10-16
CVE-2016-0249 [HIGH] CWE-89 CVE-2016-0249: SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2019-4422P3HIGHCVSS 8.8≥ 9.0, ≤ 9.5v10.6+2 more2019-10-03
CVE-2019-4422 [HIGH] CVE-2019-4422: IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.
nvd
CVE-2020-4690P3CRITICALCVSS 9.8v11.32021-09-23
CVE-2020-4690 [CRITICAL] CWE-798 CVE-2020-4690: IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.
nvd
CVE-2021-20385P3HIGHCVSS 7.2v11.22021-05-24
CVE-2021-20385 [HIGH] CVE-2021-20385: IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.
nvd
CVE-2021-20426P3CRITICALCVSS 9.8v11.22021-05-24
CVE-2021-20426 [CRITICAL] CWE-798 CVE-2021-20426: IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.
nvd
CVE-2021-20557P3HIGHCVSS 7.2v11.22021-05-24
CVE-2021-20557 [HIGH] CWE-78 CVE-2021-20557: IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
nvd
CVE-2020-4193P3CRITICALCVSS 9.8v11.12020-06-04
CVE-2020-4193 [CRITICAL] CWE-307 CVE-2020-4193: IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote atta IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
nvd
CVE-2020-4177P3CRITICALCVSS 9.8v11.12020-06-03
CVE-2020-4177 [CRITICAL] CWE-798 CVE-2020-4177: IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174732.
nvd
CVE-2018-1818P3CRITICALCVSS 9.8≥ 10.0, ≤ 10.5v10+1 more2018-12-13
CVE-2018-1818 [CRITICAL] CWE-798 CVE-2018-1818: IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptograph IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.
nvd