cbcvebase.

Ibm Security Guardium vulnerabilities

114 known vulnerabilities affecting ibm/security_guardium.

Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM60LOW5

Vulnerabilities

Page 2 of 6
CVE-2023-42004P3HIGHCVSS 8.8v11.3v11.4+2 more2023-11-28
CVE-2023-42004 [HIGH] CWE-1236 CVE-2023-42004: IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote att IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
nvd
CVE-2021-20418P3CRITICALCVSS 9.8v11.22021-08-11
CVE-2021-20418 [CRITICAL] CWE-521 CVE-2021-20418: IBM Security Guardium 11.2 does not require that users should have strong passwords by default, whic IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
nvd
CVE-2023-0041P3HIGHCVSS 8.8v11.52023-06-05
CVE-2023-0041 [HIGH] CWE-613 CVE-2023-0041: IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficien IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657.
nvd
CVE-2020-4688P3HIGHCVSS 7.8v10.6v11.22021-01-20
CVE-2020-4688 [HIGH] CWE-77 CVE-2020-4688: IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on th IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
nvd
CVE-2017-1597P3HIGHCVSS 7.5≥ 10.0, ≤ 10.5v10.0+6 more2018-12-17
CVE-2017-1597 [HIGH] CWE-521 CVE-2017-1597: IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
nvd
CVE-2021-20427P3HIGHCVSS 7.5v11.22021-08-11
CVE-2021-20427 [HIGH] CWE-307 CVE-2021-20427: IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote atta IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
nvd
CVE-2023-47712P3HIGHCVSS 7.8v11.3v11.4+3 more2024-05-14
CVE-2023-47712 [HIGH] CWE-732 CVE-2023-47712: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privilege IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
nvd
CVE-2022-43904P3HIGHCVSS 7.5v11.3v11.4+1 more2023-08-28
CVE-2022-43904 [HIGH] CWE-307 CVE-2022-43904: IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to impro IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
nvd
CVE-2017-1268P3HIGHCVSS 7.5≥ 10.0, ≤ 10.5v10+1 more2018-12-13
CVE-2017-1268 [HIGH] CWE-310 CVE-2017-1268: IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
nvd
CVE-2022-43910P3HIGHCVSS 7.8v11.32023-07-19
CVE-2022-43910 [HIGH] CWE-281 CVE-2022-43910: IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper pe IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908.
nvd
CVE-2022-22307P3HIGHCVSS 7.8v11.3v11.4+2 more2023-06-15
CVE-2022-22307 [HIGH] CWE-863 CVE-2022-22307: IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges du IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.
nvd
CVE-2021-20419P3HIGHCVSS 7.5v11.22021-05-24
CVE-2021-20419 [HIGH] CWE-327 CVE-2021-20419: IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an at IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
nvd
CVE-2017-1254P3HIGHCVSS 7.1v10.0v10.0.1+2 more2017-07-05
CVE-2017-1254 [HIGH] CWE-611 CVE-2017-1254: IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when proces IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.
nvd
CVE-2021-39076P3HIGHCVSS 7.5v10.5v11.32022-04-19
CVE-2021-39076 [HIGH] CWE-327 CVE-2021-39076: IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could al IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585.
nvd
CVE-2017-1267P3HIGHCVSS 7.5v9.0v9.1+5 more2017-07-21
CVE-2017-1267 [HIGH] CWE-20 CVE-2017-1267: IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without suffi IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.
nvd
CVE-2018-1501P3HIGHCVSS 7.5v10.5v10.6+1 more2020-08-26
CVE-2018-1501 [HIGH] CWE-306 CVE-2018-1501: IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive info IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226.
nvd
CVE-2016-6065P3HIGHCVSS 7.8v8.2v9.0+6 more2017-02-01
CVE-2016-6065 [HIGH] CWE-78 CVE-2016-6065: IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject command IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
nvd
CVE-2021-20389P3HIGHCVSS 7.8v11.22021-05-24
CVE-2021-20389 [HIGH] CWE-522 CVE-2021-20389: IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
nvd
CVE-2017-1271P3HIGHCVSS 7.5v9.0v9.1+1 more2017-12-07
CVE-2017-1271 [HIGH] CWE-326 CVE-2017-1271: IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows thos IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.
nvd
CVE-2020-4185P3HIGHCVSS 7.5v10.5v10.6+1 more2020-07-30
CVE-2020-4185 [HIGH] CWE-327 CVE-2020-4185: IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that c IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803.
nvd
Ibm Security Guardium vulnerabilities | cvebase