CVE-2025-36020
- EPSS 0.02%
- Veröffentlicht 06.08.2025 14:28:45
- Zuletzt bearbeitet 13.08.2025 18:21:56
IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.
CVE-2025-3473
- EPSS 0.01%
- Veröffentlicht 11.06.2025 14:24:46
- Zuletzt bearbeitet 13.08.2025 14:26:30
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
CVE-2025-25029
- EPSS 0.05%
- Veröffentlicht 28.05.2025 01:12:19
- Zuletzt bearbeitet 04.06.2025 14:34:42
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
CVE-2025-25026
- EPSS 0.05%
- Veröffentlicht 28.05.2025 01:11:23
- Zuletzt bearbeitet 04.06.2025 14:34:34
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
CVE-2025-25025
- EPSS 0.06%
- Veröffentlicht 28.05.2025 01:10:05
- Zuletzt bearbeitet 04.06.2025 14:34:21
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2025-3440
- EPSS 0.05%
- Veröffentlicht 15.05.2025 15:40:34
- Zuletzt bearbeitet 16.05.2025 14:43:26
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu...
CVE-2025-25023
- EPSS 0.03%
- Veröffentlicht 09.04.2025 14:15:28
- Zuletzt bearbeitet 20.06.2025 16:59:29
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.
CVE-2024-49336
- EPSS 0.07%
- Veröffentlicht 19.12.2024 18:15:22
- Zuletzt bearbeitet 25.02.2025 12:15:30
IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2023-47710
- EPSS 0.08%
- Veröffentlicht 24.05.2024 12:15:08
- Zuletzt bearbeitet 08.01.2025 20:17:26
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure ...
CVE-2023-47717
- EPSS 0.04%
- Veröffentlicht 16.05.2024 18:15:08
- Zuletzt bearbeitet 13.06.2025 19:04:54
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.