cbcvebase.

Ibm Security Guardium vulnerabilities

114 known vulnerabilities affecting ibm/security_guardium.

Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM60LOW5

Vulnerabilities

Page 3 of 6
CVE-2018-1509P3HIGHCVSS 7.4v10.52018-10-02
CVE-2018-1509 [HIGH] CWE-295 CVE-2018-1509: IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that
nvd
CVE-2020-4689P3MEDIUMCVSS 6.8v11.22020-10-12
CVE-2020-4689 [MEDIUM] CWE-1236 CVE-2020-4689: IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execut IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
nvd
CVE-2020-4184P3HIGHCVSS 7.3v11.22021-03-15
CVE-2020-4184 [HIGH] CWE-269 CVE-2020-4184: IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimu IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..
nvd
CVE-2017-1264P3HIGHCVSS 7.5v10.0v10.0.1+2 more2017-07-05
CVE-2017-1264 [HIGH] CWE-287 CVE-2017-1264: IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is corre IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.
nvd
CVE-2017-1255P3HIGHCVSS 7.5v10.0v10.0.1+4 more2018-05-02
CVE-2017-1255 [HIGH] CWE-326 CVE-2017-1255: IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
nvd
CVE-2017-1598P3HIGHCVSS 7.5v10.0v10.0.1+4 more2017-12-20
CVE-2017-1598 [HIGH] CWE-327 CVE-2017-1598: IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorit IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.
nvd
CVE-2017-1122P3HIGHCVSS 7.4v8.2v9.0+7 more2017-04-20
CVE-2017-1122 [HIGH] CVE-2017-1122: IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.
nvd
CVE-2016-0298P3MEDIUMCVSS 6.5≤ 10.02016-06-29
CVE-2016-0298 [MEDIUM] CWE-200 CVE-2016-0298: Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
nvd
CVE-2025-25029P3MEDIUMCVSS 6.5v12.02025-05-28
CVE-2025-25029 [MEDIUM] CWE-116 CVE-2025-25029: IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to i IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
nvd
CVE-2023-33852P3MEDIUMCVSS 5.4v11.42023-08-27
CVE-2023-33852 [MEDIUM] CWE-89 CVE-2023-33852: IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially cr IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.
nvd
CVE-2018-1498P4HIGHCVSS 7.8v10.52018-10-02
CVE-2018-1498 [HIGH] CWE-522 CVE-2018-1498: IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be rea IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.
nvd
CVE-2016-0247P4HIGHCVSS 7.8v8.2v9.0+5 more2016-10-22
CVE-2016-0247 [HIGH] CWE-200 CVE-2016-0247: IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p10 IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.
nvd
CVE-2021-20433P4MEDIUMCVSS 6.5v11.32021-09-15
CVE-2021-20433 [MEDIUM] CVE-2021-20433: IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.
nvd
CVE-2023-47711P4MEDIUMCVSS 6.5v11.3v11.4+3 more2024-05-14
CVE-2023-47711 [MEDIUM] CWE-434 CVE-2023-47711: IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files t IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.
nvd
CVE-2024-49336P4MEDIUMCVSS 5.4v11.5v12.0+1 more2024-12-19
CVE-2024-49336 [MEDIUM] CWE-918 CVE-2024-49336: IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may al IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2017-1258P4MEDIUMCVSS 6.5v10.0v10.0.1+2 more2017-07-05
CVE-2017-1258 [MEDIUM] CWE-287 CVE-2017-1258: IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685
nvd
CVE-2022-43908P4MEDIUMCVSS 6.5v11.32023-07-19
CVE-2022-43908 [MEDIUM] CWE-20 CVE-2022-43908: IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to im IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903.
nvd
CVE-2022-43903P4MEDIUMCVSS 6.5v10.6v11.3+2 more2023-09-05
CVE-2022-43903 [MEDIUM] CWE-20 CVE-2022-43903: IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of se IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
nvd
CVE-2025-3473P4MEDIUMCVSS 6.7v12.12025-06-11
CVE-2025-3473 [MEDIUM] CWE-277 CVE-2025-3473: IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
nvd
CVE-2020-4190P4MEDIUMCVSS 6.7v10.6v11.0+1 more2020-06-03
CVE-2020-4190 [MEDIUM] CWE-798 CVE-2020-4190: IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cr IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174851.
nvd
Ibm Security Guardium vulnerabilities | cvebase