VYPR

Security Guardium

by IBM

CVEs (137)

  • CVE-2020-4597MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to…

  • CVE-2020-4171MedAug 27, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174407.

  • CVE-2020-4170MedAug 24, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406.

  • CVE-2017-1257MedDec 20, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

  • CVE-2016-0242MedOct 22, 2016
    risk 0.28cvss 4.3epss 0.01

    IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.

  • CVE-2017-1272LowDec 17, 2018
    risk 0.24cvss 3.7epss 0.02

    IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 124747. IBM X-Force ID: 124747.

  • CVE-2017-1265LowDec 17, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) techniques. IBM X-Force ID: 124740.

  • CVE-2018-1509LowOct 2, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a…

  • CVE-2016-0238LowJul 5, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409

  • CVE-2016-0248LowSep 26, 2016
    risk 0.24cvss 3.7epss 0.01

    IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.

  • CVE-2017-1270LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 124745.

  • CVE-2017-1261LowDec 20, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

  • CVE-2022-43906LowOct 4, 2023
    risk 0.20cvss 3.1epss 0.00

    IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.

  • CVE-2023-47711LowMay 14, 2024
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.

  • CVE-2021-29846LowJan 26, 2022
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

  • CVE-2021-20377LowSep 23, 2021
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

  • CVE-2015-5043Nov 8, 2015
    risk 0.00cvss epss 0.00

    diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.

Page 7 of 7