VYPR

Security Guardium

by IBM

CVEs (137)

  • CVE-2017-1595MedDec 20, 2017
    risk 0.36cvss 5.5epss 0.00

    IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.

  • CVE-2017-1600MedDec 20, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2017-1266MedDec 20, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.

  • CVE-2018-1368MedFeb 9, 2018
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not…

  • CVE-2017-1257MedDec 20, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

  • CVE-2016-0242MedOct 22, 2016
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.

  • CVE-2018-1509LowOct 2, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a…

  • CVE-2016-0238LowJul 5, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409

  • CVE-2016-0248LowSep 26, 2016
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.

  • CVE-2017-1270LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.

  • CVE-2017-1261LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

  • CVE-2020-4180Jun 3, 2020
    risk 0.01cvss epss 0.03

    IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.

  • CVE-2025-3473Jun 11, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

  • CVE-2025-25029May 28, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

  • CVE-2025-25026May 28, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

  • CVE-2025-25025May 28, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

  • CVE-2025-3440May 15, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

  • CVE-2025-25023Apr 9, 2025
    risk 0.00cvss epss 0.00

    IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.

  • CVE-2024-49336Dec 19, 2024
    risk 0.00cvss epss 0.00

    IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2023-47710May 24, 2024
    risk 0.00cvss epss 0.00

    IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

Page 2 of 7