Security Guardium
by IBM
CVEs (137)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-25023 | Med | 0.32 | 4.9 | 0.00 | Apr 9, 2025 | IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment. | ||
| CVE-2020-4678 | Med | 0.32 | 4.9 | 0.01 | Oct 12, 2020 | IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to. IBM X-Force ID: 186423. | ||
| CVE-2020-4679 | Med | 0.31 | 4.8 | 0.01 | Oct 12, 2020 | IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | ||
| CVE-2022-43909 | Med | 0.30 | 4.6 | 0.00 | Aug 27, 2023 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: … | ||
| CVE-2023-47717 | Med | 0.29 | 4.4 | 0.00 | May 16, 2024 | IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690. | ||
| CVE-2022-22307 | Med | 0.29 | 4.4 | 0.00 | Jun 15, 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. | ||
| CVE-2022-39166 | Med | 0.29 | 4.4 | 0.01 | Dec 20, 2022 | IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405. | ||
| CVE-2021-39077 | Med | 0.29 | 4.4 | 0.00 | Nov 3, 2022 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587. | ||
| CVE-2021-39078 | Med | 0.29 | 4.4 | 0.00 | Apr 19, 2022 | IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589. | ||
| CVE-2020-4604 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 184861. | ||
| CVE-2020-4602 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2021 | IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836. | ||
| CVE-2020-4593 | Med | 0.29 | 4.4 | 0.00 | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747. | ||
| CVE-2020-4191 | Med | 0.29 | 4.4 | 0.00 | Jun 4, 2020 | IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852. | ||
| CVE-2018-1368 | Med | 0.29 | 4.4 | 0.00 | Feb 9, 2018 | IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not… | ||
| CVE-2025-25026 | Med | 0.28 | 4.3 | 0.00 | May 28, 2025 | IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check. | ||
| CVE-2025-25025 | Med | 0.28 | 4.3 | 0.00 | May 28, 2025 | IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | ||
| CVE-2022-43903 | Med | 0.28 | 4.3 | 0.01 | Sep 5, 2023 | IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894. | ||
| CVE-2022-43908 | Med | 0.28 | 4.3 | 0.01 | Jul 19, 2023 | IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903. | ||
| CVE-2021-20420 | Med | 0.28 | 4.3 | 0.01 | Aug 11, 2021 | IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281. | ||
| CVE-2020-4189 | Med | 0.28 | 4.3 | 0.01 | Jan 27, 2021 | IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850. |
- risk 0.32cvss 4.9epss 0.00
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
- risk 0.32cvss 4.9epss 0.01
IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to. IBM X-Force ID: 186423.
- risk 0.31cvss 4.8epss 0.01
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:…
- risk 0.30cvss 4.6epss 0.00
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: …
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.
- risk 0.29cvss 4.4epss 0.01
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 184861.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852.
- risk 0.29cvss 4.4epss 0.00
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not…
- risk 0.28cvss 4.3epss 0.00
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
- risk 0.28cvss 4.3epss 0.00
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
- risk 0.28cvss 4.3epss 0.01
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.
- risk 0.28cvss 4.3epss 0.01
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903.
- risk 0.28cvss 4.3epss 0.01
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.
- risk 0.28cvss 4.3epss 0.01
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850.
Page 6 of 7