Ibm Security Guardium vulnerabilities
114 known vulnerabilities affecting ibm/security_guardium.
Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM60LOW5
Vulnerabilities
Page 1 of 6
CVE-2025-3473MEDIUMCVSS 6.7v12.12025-06-11
CVE-2025-3473 [MEDIUM] CWE-277 CVE-2025-3473: IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
cvelistv5nvd
CVE-2025-25025MEDIUMCVSS 5.3v12.02025-05-28
CVE-2025-25025 [MEDIUM] CWE-209 CVE-2025-25025: IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a deta
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2025-25029MEDIUMCVSS 6.5v12.02025-05-28
CVE-2025-25029 [MEDIUM] CWE-116 CVE-2025-25029: IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to i
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
cvelistv5nvd
CVE-2025-25026MEDIUMCVSS 4.3v12.02025-05-28
CVE-2025-25026 [MEDIUM] CWE-863 CVE-2025-25026: IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
cvelistv5nvd
CVE-2025-3440MEDIUMCVSS 5.5v11.5v12.02025-05-15
CVE-2025-3440 [MEDIUM] CWE-79 CVE-2025-3440: IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-25023MEDIUMCVSS 4.9≥ 11.4, ≤ 12.1v11.4, 12.12025-04-09
CVE-2025-25023 [MEDIUM] CWE-266 CVE-2025-25023: IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
cvelistv5nvd
CVE-2024-49336MEDIUMCVSS 5.4v11.5v12.0+1 more2024-12-19
CVE-2024-49336 [MEDIUM] CWE-918 CVE-2024-49336: IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may al
IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
cvelistv5nvd
CVE-2023-47710MEDIUMCVSS 5.4v11.4v11.5+2 more2024-05-24
CVE-2023-47710 [MEDIUM] CWE-79 CVE-2023-47710: IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525.
cvelistv5nvd
CVE-2023-47717MEDIUMCVSS 4.4v12.02024-05-16
CVE-2023-47717 [MEDIUM] CWE-770 CVE-2023-47717: IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.
cvelistv5nvd
CVE-2023-47712HIGHCVSS 7.8v11.3v11.4+3 more2024-05-14
CVE-2023-47712 [HIGH] CWE-732 CVE-2023-47712: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privilege
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
cvelistv5nvd
CVE-2023-47709HIGHCVSS 8.8v11.3v11.4+3 more2024-05-14
CVE-2023-47709 [CRITICAL] CWE-78 CVE-2023-47709: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to exec
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
cvelistv5nvd
CVE-2023-47711MEDIUMCVSS 6.5v11.3v11.4+3 more2024-05-14
CVE-2023-47711 [LOW] CWE-434 CVE-2023-47711: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files t
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
cvelistv5nvd
CVE-2023-42004HIGHCVSS 8.8v11.3v11.4+2 more2023-11-28
CVE-2023-42004 [HIGH] CWE-1236 CVE-2023-42004: IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote att
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
cvelistv5nvd
CVE-2022-43906MEDIUMCVSS 5.3v11.52023-10-04
CVE-2022-43906 [LOW] CVE-2022-43906: IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSit
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.
cvelistv5nvd
CVE-2022-43903MEDIUMCVSS 6.5v10.6v11.3+2 more2023-09-05
CVE-2022-43903 [MEDIUM] CWE-20 CVE-2022-43903: IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of se
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
cvelistv5nvd
CVE-2022-43904HIGHCVSS 7.5v11.3v11.4+1 more2023-08-28
CVE-2022-43904 [HIGH] CWE-307 CVE-2022-43904: IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to impro
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
cvelistv5nvd
CVE-2022-43907HIGHCVSS 8.8v11.42023-08-27
CVE-2022-43907 [HIGH] CWE-78 CVE-2022-43907: IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands
IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.
cvelistv5nvd
CVE-2023-30435MEDIUMCVSS 5.4v11.3v11.4+2 more2023-08-27
CVE-2023-30435 [HIGH] CWE-79 CVE-2023-30435: IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulner
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.
cvelistv5nvd
CVE-2023-30437MEDIUMCVSS 5.3v11.3v11.4+2 more2023-08-27
CVE-2023-30437 [MEDIUM] CVE-2023-30437: IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames b
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
cvelistv5nvd
CVE-2022-43909MEDIUMCVSS 5.4v11.42023-08-27
CVE-2022-43909 [MEDIUM] CWE-79 CVE-2022-43909: IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905.
cvelistv5nvd
1 / 6Next →