VendorsIBMsecurity_guardiumall versions
Vulnerabilities

IBM Security Guardium

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-2017-1253
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.
Published 2017-07-05 · Modified
9.9EPSS 0.023
CVE-2023-35893
IBM Security Guardium command execution
Published 2023-08-16 · Modified
9.9EPSS 0.014
CVE-2017-1269
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744
Published 2017-07-05 · Modified
9.8EPSS 0.019
CVE-2020-4193
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
Published 2020-06-04 · Modified
9.8EPSS 0.014
CVE-2020-4690
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.
Published 2021-09-23 · Modified
9.8EPSS 0.011
CVE-2020-4177
IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174732.
Published 2020-06-03 · Modified
9.8EPSS 0.010
CVE-2021-20426
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.
Published 2021-05-24 · Modified
9.8EPSS 0.010
CVE-2021-20418
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
Published 2021-08-11 · Modified
9.8EPSS 0.010
CVE-2018-1818
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.
Published 2018-12-13 · Modified
9.8EPSS 0.008
CVE-2023-47709
IBM Security Guardium command injection
Published 2024-05-11 · Analyzed
9.1EPSS 0.010
CVE-2020-4180
IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.
Published 2020-06-03 · Modified
9.0EPSS 0.030
CVE-2021-20557
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
Published 2021-05-24 · Modified
9.0EPSS 0.027
CVE-2021-20385
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.
Published 2021-05-24 · Modified
9.0EPSS 0.021
CVE-2020-4952
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028.
Published 2021-01-27 · Modified
9.0EPSS 0.020
CVE-2023-30435
IBM Security Guardium cross-site scripting
Published 2023-08-27 · Modified
8.9EPSS 0.004
CVE-2019-4292
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698.
Published 2019-07-02 · Modified
8.8EPSS 0.037
CVE-2019-4422
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.
Published 2019-10-03 · Modified
8.8EPSS 0.017
CVE-2017-1757
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.
Published 2017-12-20 · Modified
8.8EPSS 0.016
CVE-2020-4921
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.
Published 2021-01-20 · Modified
8.8EPSS 0.015
CVE-2022-43907
IBM Security Guardium command execution
Published 2023-08-27 · Modified
8.8EPSS 0.013
CVE-2020-4990
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
Published 2021-05-24 · Modified
8.8EPSS 0.011
CVE-2023-42004
IBM Security Guardium CSV injection
Published 2023-11-28 · Modified
8.8EPSS 0.011
CVE-2023-0041
IBM Security Guardium session fixation
Published 2023-06-05 · Modified
8.8EPSS 0.005
CVE-2016-0249
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2016-10-16 · Modified
8.6EPSS 0.015
CVE-2020-4689
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
Published 2020-10-12 · Modified
8.5EPSS 0.024
CVE-2022-43910
IBM Security Guardium privilege escalation
Published 2023-07-19 · Modified
8.4EPSS 0.002
CVE-2020-4688
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
Published 2021-01-20 · Modified
7.8EPSS 0.009
CVE-2016-6065
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
Published 2017-02-01 · Modified
7.8EPSS 0.004
CVE-2018-1498
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.
Published 2018-10-02 · Modified
7.8EPSS 0.004
CVE-2016-0247
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.
Published 2016-10-22 · Modified
7.8EPSS 0.003
CVE-2021-20389
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
Published 2021-05-24 · Modified
7.8EPSS 0.002
CVE-2023-47712
IBM Security Guardium privilege escalation
Published 2024-05-11 · Analyzed
7.8EPSS 0.002
CVE-2022-22307
IBM Security Guardium privilege escalation
Published 2023-06-15 · Modified
7.8EPSS 0.002
CVE-2023-33852
IBM Security Guardium SQL injection
Published 2023-08-27 · Modified
7.6EPSS 0.006
CVE-2017-1597
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
Published 2018-12-17 · Modified
7.5EPSS 0.020
CVE-2017-1267
IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.
Published 2017-07-21 · Modified
7.5EPSS 0.016
CVE-2017-1264
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.
Published 2017-07-05 · Modified
7.5EPSS 0.015
CVE-2017-1268
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
Published 2018-12-13 · Modified
7.5EPSS 0.013
CVE-2021-20427
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.
Published 2021-08-11 · Modified
7.5EPSS 0.013
CVE-2018-1501
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls. IBM X-Force ID: 141226.
Published 2020-08-26 · Modified
7.5EPSS 0.011
1 / 3Next →