VendorsIBMsecurity_guardiumall versions
Vulnerabilities

IBM Security Guardium

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-2017-1255
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.
Published 2018-05-02 · Modified
7.5EPSS 0.011
CVE-2017-1598
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.
Published 2017-12-20 · Modified
7.5EPSS 0.008
CVE-2017-1271
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.
Published 2017-12-07 · Modified
7.5EPSS 0.008
CVE-2020-4184
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..
Published 2021-03-15 · Modified
7.5EPSS 0.008
CVE-2020-4185
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803.
Published 2020-07-30 · Modified
7.5EPSS 0.008
CVE-2022-43904
IBM Security Guardium information disclosure
Published 2023-08-27 · Modified
7.5EPSS 0.008
CVE-2021-20419
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
Published 2021-05-24 · Modified
7.5EPSS 0.007
CVE-2021-39076
IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 215585.
Published 2022-04-19 · Modified
7.5EPSS 0.006
CVE-2018-1509
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 141417.
Published 2018-10-02 · Modified
7.4EPSS 0.009
CVE-2017-1122
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.
Published 2017-04-20 · Modified
7.4EPSS 0.003
CVE-2015-5043
diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.
Published 2015-11-08 · Modified
7.2EPSS 0.003
CVE-2017-1254
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.
Published 2017-07-05 · Modified
7.1EPSS 0.016
CVE-2020-4190
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174851.
Published 2020-06-03 · Modified
6.7EPSS 0.002
CVE-2016-0298
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
Published 2016-06-29 · Modified
6.5EPSS 0.013
CVE-2017-1258
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685
Published 2017-07-05 · Modified
6.5EPSS 0.011
CVE-2021-20433
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.
Published 2021-09-15 · Modified
6.5EPSS 0.009
CVE-2022-43903
IBM Security Guardium denial of service
Published 2023-09-04 · Modified
6.5EPSS 0.007
CVE-2022-43908
IBM Security Guardium denial of service
Published 2023-07-19 · Modified
6.5EPSS 0.007
CVE-2023-47711
IBM Security Guardium denial of service
Published 2024-05-11 · Analyzed
6.5EPSS 0.007
CVE-2020-4307
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM X-Force ID: 176997.
Published 2020-06-03 · Modified
6.5EPSS 0.005
CVE-2025-25029
IBM Security Guardium information disclosure
Published 2025-05-28 · Analyzed
6.5EPSS 0.004
CVE-2024-49336
IBM Security Guardium server-side request forgery
Published 2024-12-19 · Analyzed
6.5EPSS 0.002
CVE-2017-1262
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.
Published 2017-12-20 · Modified
6.1EPSS 0.013
CVE-2018-1817
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150021.
Published 2018-12-13 · Modified
6.1EPSS 0.009
CVE-2017-1256
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678
Published 2017-07-05 · Modified
6.1EPSS 0.008
CVE-2016-0246
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2016-10-22 · Modified
6.1EPSS 0.008
CVE-2020-4182
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174738.
Published 2020-06-03 · Modified
6.1EPSS 0.007
CVE-2020-4183
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.
Published 2020-06-04 · Modified
6.1EPSS 0.007
CVE-2021-20386
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.
Published 2021-05-24 · Modified
6.1EPSS 0.007
CVE-2021-39074
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2022-06-29 · Modified
6.1EPSS 0.006
CVE-2021-39072
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 215581.
Published 2022-04-19 · Modified
5.9EPSS 0.013
CVE-2017-1265
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) techniques. IBM X-Force ID: 124740.
Published 2018-12-17 · Modified
5.9EPSS 0.008
CVE-2021-29773
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865.
Published 2021-09-15 · Modified
5.5EPSS 0.007
CVE-2017-1266
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.
Published 2017-12-20 · Modified
5.5EPSS 0.005
CVE-2023-30436
IBM Security Guardium cross-site scripting
Published 2023-08-27 · Modified
5.5EPSS 0.003
CVE-2017-1595
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.
Published 2017-12-20 · Modified
5.5EPSS 0.003
CVE-2017-1596
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550.
Published 2017-12-20 · Modified
5.5EPSS 0.003
CVE-2025-3440
IBM Security Guardium cross-site scripting
Published 2025-05-15 · Analyzed
5.5EPSS 0.002
CVE-2018-1889
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.
Published 2018-12-17 · Modified
5.4EPSS 0.010
CVE-2018-1891
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152082.
Published 2018-12-17 · Modified
5.4EPSS 0.010
← Prev2 / 3Next →