Ibm

Security Guardium

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

  • EPSS 0.05%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.

  • EPSS 0.32%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the ...

  • EPSS 0.09%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.

  • EPSS 0.05%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID:...

  • EPSS 0.05%
  • Veröffentlicht 20.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.

  • EPSS 0.06%
  • Veröffentlicht 07.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strong...

  • EPSS 0.78%
  • Veröffentlicht 21.07.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.

  • EPSS 1.36%
  • Veröffentlicht 05.07.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM ...

  • EPSS 0.47%
  • Veröffentlicht 05.07.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: ...