IBM
IBM Security Guardium: vulnerabilidades y CVE
IBM Security Guardium tiene 112 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE112
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-25029 | Media (6.5) | 0.39% | — | 28 may 2025 | IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input. |
| CVE-2025-25026 | Media (4.3) | 0.28% | — | 28 may 2025 | IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check. |
| CVE-2025-25025 | Media (5.3) | 0.34% | — | 28 may 2025 | IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the… |
| CVE-2025-3440 | Media (5.5) | 0.24% | — | 15 may 2025 | IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2025-25023 | Media (4.9) | 0.35% | — | 9 abr 2025 | IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment. |
| CVE-2024-49336 | Media (5.4) | 0.22% | — | 19 dic 2024 | IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration… |
| CVE-2023-47710 | Media (5.4) | 0.25% | — | 24 may 2024 | IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2023-47717 | Media (4.4) | 0.17% | — | 16 may 2024 | IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690. |
| CVE-2023-47712 | Alta (7.8) | 0.19% | — | 14 may 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527. |
| CVE-2023-47711 | Media (6.5) | 0.68% | — | 14 may 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526. |
| CVE-2023-47709 | Alta (8.8) | 1.0% | — | 14 may 2024 | IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524. |
| CVE-2023-42004 | Alta (8.8) | 1.1% | — | 28 nov 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. |
| CVE-2022-43906 | Media (5.3) | 0.47% | — | 4 oct 2023 | IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. |
| CVE-2022-43903 | Media (6.5) | 0.71% | — | 5 sept 2023 | IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894. |
| CVE-2022-43904 | Alta (7.5) | 0.77% | — | 28 ago 2023 | IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895. |
| CVE-2023-33852 | Media (5.4) | 0.56% | — | 27 ago 2023 | IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end… |
| CVE-2023-30437 | Media (5.3) | 0.60% | — | 27 ago 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293. |
| CVE-2023-30436 | Media (5.4) | 0.34% | — | 27 ago 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… |
| CVE-2023-30435 | Media (5.4) | 0.42% | — | 27 ago 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2022-43909 | Media (5.4) | 0.37% | — | 27 ago 2023 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2022-43907 | Alta (8.8) | 1.3% | — | 27 ago 2023 | IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901. |
| CVE-2023-35893 | Alta (8.8) | 1.4% | — | 16 ago 2023 | IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. |
| CVE-2022-43910 | Alta (7.8) | 0.17% | — | 19 jul 2023 | IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908. |
| CVE-2022-43908 | Media (6.5) | 0.71% | — | 19 jul 2023 | IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903. |
| CVE-2022-22307 | Alta (7.8) | 0.16% | — | 15 jun 2023 | IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. |
| CVE-2023-0041 | Alta (8.8) | 0.46% | — | 5 jun 2023 | IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657. |
| CVE-2022-39166 | Media (4.9) | 0.60% | — | 20 dic 2022 | IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force ID: 235405. |
| CVE-2021-39077 | Media (4.4) | 0.13% | — | 3 nov 2022 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587. |
| CVE-2021-39074 | Media (6.1) | 0.61% | — | 29 jun 2022 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2021-39078 | Media (4.4) | 0.14% | — | 19 abr 2022 | IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589. |
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142