Skip to main content

Vendor/product archive

ibm / security_guardium CVEs

Beta · best-effort

112 CVEs tagged to ibm / security_guardium9 Critical, 35 High, 58 Medium, 10 Low, 0 Unrated.

CVE-2025-25029

Published May 28, 2025

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25026

Published May 28, 2025

IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25025

Published May 28, 2025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information coul…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3440

Published May 15, 2025

IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25023

Published Apr 9, 2025

IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-49336

Published Dec 19, 2024

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, po…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47710

Published May 24, 2024

IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47717

Published May 16, 2024

IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47712

Published May 14, 2024

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47711

Published May 14, 2024

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-47709

Published May 14, 2024

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. I…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-42004

Published Nov 28, 2023

IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file c…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43906

Published Oct 4, 2023

IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-43904

Published Aug 28, 2023

IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33852

Published Aug 27, 2023

IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or de…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30437

Published Aug 27, 2023

IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30436

Published Aug 27, 2023

IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30435

Published Aug 27, 2023

IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alte…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43909

Published Aug 27, 2023

IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43907

Published Aug 27, 2023

IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35893

Published Aug 16, 2023

IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. I…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 112 CVEsPage 1 of 5