Security Guardium
by IBM
CVEs (137)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42004 | Hig | 0.52 | 8.0 | 0.01 | Nov 28, 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. | ||
| CVE-2023-47712 | Hig | 0.51 | 7.8 | 0.00 | May 14, 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527. | ||
| CVE-2021-20389 | Hig | 0.51 | 7.8 | 0.00 | May 24, 2021 | IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770. | ||
| CVE-2020-4688 | Hig | 0.51 | 7.8 | 0.01 | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700. | ||
| CVE-2016-6065 | Hig | 0.51 | 7.8 | 0.00 | Feb 1, 2017 | IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root. | ||
| CVE-2016-0247 | Hig | 0.51 | 7.8 | 0.00 | Oct 22, 2016 | IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information. | ||
| CVE-2022-43904 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2023 | IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895. | ||
| CVE-2023-33852 | Hig | 0.49 | 7.6 | 0.00 | Aug 27, 2023 | IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614. | ||
| CVE-2021-39076 | Hig | 0.49 | 7.5 | 0.01 | Apr 19, 2022 | IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585. | ||
| CVE-2021-20427 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2021 | IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314. | ||
| CVE-2021-20419 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2021 | IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. | ||
| CVE-2020-4596 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812. | ||
| CVE-2020-4595 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819. | ||
| CVE-2020-4594 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800. | ||
| CVE-2020-4174 | Hig | 0.49 | 7.5 | 0.01 | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174683. | ||
| CVE-2020-4169 | Hig | 0.49 | 7.5 | 0.01 | Aug 27, 2020 | IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405. | ||
| CVE-2018-1501 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2020 | IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226. | ||
| CVE-2020-4185 | Hig | 0.49 | 7.5 | 0.01 | Jul 30, 2020 | IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803. | ||
| CVE-2017-1255 | Hig | 0.49 | 7.5 | 0.01 | May 2, 2018 | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675. | ||
| CVE-2017-1598 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2017 | IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611. |
- risk 0.52cvss 8.0epss 0.01
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
- risk 0.51cvss 7.8epss 0.00
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.
- risk 0.51cvss 7.8epss 0.00
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
- risk 0.51cvss 7.8epss 0.01
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
- risk 0.51cvss 7.8epss 0.00
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
- risk 0.51cvss 7.8epss 0.00
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
- risk 0.49cvss 7.6epss 0.00
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184812.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184819.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174683.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.
Page 2 of 7