Ibm Security Guardium vulnerabilities

114 known vulnerabilities affecting ibm/security_guardium.

Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM60LOW5

Vulnerabilities

Page 1 of 6
CVE-2025-3473MEDIUMCVSS 6.7v12.12025-06-11
CVE-2025-3473 [MEDIUM] CWE-277 CVE-2025-3473: IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
cvelistv5nvd
CVE-2025-25025MEDIUMCVSS 5.3v12.02025-05-28
CVE-2025-25025 [MEDIUM] CWE-209 CVE-2025-25025: IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a deta IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2025-25029MEDIUMCVSS 6.5v12.02025-05-28
CVE-2025-25029 [MEDIUM] CWE-116 CVE-2025-25029: IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to i IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
cvelistv5nvd
CVE-2025-25026MEDIUMCVSS 4.3v12.02025-05-28
CVE-2025-25026 [MEDIUM] CWE-863 CVE-2025-25026: IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
cvelistv5nvd
CVE-2025-3440MEDIUMCVSS 5.5v11.5v12.02025-05-15
CVE-2025-3440 [MEDIUM] CWE-79 CVE-2025-3440: IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-25023MEDIUMCVSS 4.9≥ 11.4, ≤ 12.1v11.4, 12.12025-04-09
CVE-2025-25023 [MEDIUM] CWE-266 CVE-2025-25023: IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
cvelistv5nvd
CVE-2024-49336MEDIUMCVSS 5.4v11.5v12.0+1 more2024-12-19
CVE-2024-49336 [MEDIUM] CWE-918 CVE-2024-49336: IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may al IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
cvelistv5nvd
CVE-2023-47710MEDIUMCVSS 5.4v11.4v11.5+2 more2024-05-24
CVE-2023-47710 [MEDIUM] CWE-79 CVE-2023-47710: IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525.
cvelistv5nvd
CVE-2023-47717MEDIUMCVSS 4.4v12.02024-05-16
CVE-2023-47717 [MEDIUM] CWE-770 CVE-2023-47717: IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.
cvelistv5nvd
CVE-2023-47712HIGHCVSS 7.8v11.3v11.4+3 more2024-05-14
CVE-2023-47712 [HIGH] CWE-732 CVE-2023-47712: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privilege IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
cvelistv5nvd
CVE-2023-47709HIGHCVSS 8.8v11.3v11.4+3 more2024-05-14
CVE-2023-47709 [CRITICAL] CWE-78 CVE-2023-47709: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to exec IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.
cvelistv5nvd
CVE-2023-47711MEDIUMCVSS 6.5v11.3v11.4+3 more2024-05-14
CVE-2023-47711 [LOW] CWE-434 CVE-2023-47711: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files t IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
cvelistv5nvd
CVE-2023-42004HIGHCVSS 8.8v11.3v11.4+2 more2023-11-28
CVE-2023-42004 [HIGH] CWE-1236 CVE-2023-42004: IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote att IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
cvelistv5nvd
CVE-2022-43906MEDIUMCVSS 5.3v11.52023-10-04
CVE-2022-43906 [LOW] CVE-2022-43906: IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSit IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.
cvelistv5nvd
CVE-2022-43903MEDIUMCVSS 6.5v10.6v11.3+2 more2023-09-05
CVE-2022-43903 [MEDIUM] CWE-20 CVE-2022-43903: IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of se IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
cvelistv5nvd
CVE-2022-43904HIGHCVSS 7.5v11.3v11.4+1 more2023-08-28
CVE-2022-43904 [HIGH] CWE-307 CVE-2022-43904: IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to impro IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
cvelistv5nvd
CVE-2022-43907HIGHCVSS 8.8v11.42023-08-27
CVE-2022-43907 [HIGH] CWE-78 CVE-2022-43907: IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.
cvelistv5nvd
CVE-2023-30435MEDIUMCVSS 5.4v11.3v11.4+2 more2023-08-27
CVE-2023-30435 [HIGH] CWE-79 CVE-2023-30435: IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulner IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291.
cvelistv5nvd
CVE-2023-30437MEDIUMCVSS 5.3v11.3v11.4+2 more2023-08-27
CVE-2023-30437 [MEDIUM] CVE-2023-30437: IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames b IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
cvelistv5nvd
CVE-2022-43909MEDIUMCVSS 5.4v11.42023-08-27
CVE-2022-43909 [MEDIUM] CWE-79 CVE-2022-43909: IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905.
cvelistv5nvd