Home/Product/ibm security guardium
Product

ibm security guardium

112 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-25029
all versions
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
4.9MEDIUM
CVE-2025-25026
all versions
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication ch
4.3MEDIUM
CVE-2025-25025
all versions
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
4.3MEDIUM
CVE-2025-3440
all versions
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbi
5.5MEDIUM
CVE-2025-25023
>= 11.4 and <= 12.1
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assign
4.9MEDIUM
CVE-2024-49336
all versions
IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker
6.5MEDIUM
CVE-2023-47710
all versions
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
5.4MEDIUM
CVE-2023-47717
all versions
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service.
4.4MEDIUM
CVE-2023-47712
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to imprope
7.8HIGH
CVE-2023-47711
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of se
2.7LOW
CVE-2023-47709
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the
9.1CRITICAL
CVE-2023-42004
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious
8.0HIGH
CVE-2022-43906
all versions
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive co
3.1LOW
CVE-2022-43903
all versions
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper i
4.3MEDIUM
CVE-2022-43904
all versions
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive a
7.5HIGH
CVE-2023-33852
all versions
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which co
7.6HIGH
CVE-2023-30437
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted
5.3MEDIUM
CVE-2023-30436
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
5.5MEDIUM
CVE-2023-30435
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed
8.9HIGH
CVE-2022-43909
all versions
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
4.6MEDIUM
CVE-2022-43907
all versions
IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a sp
7.2HIGH
CVE-2023-35893
all versions
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the
9.9CRITICAL
CVE-2022-43910
all versions
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force
8.4HIGH
CVE-2022-43908
all versions
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-
4.3MEDIUM
CVE-2022-22307
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization c
4.4MEDIUM
CVE-2023-0041
all versions
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-F
6.3MEDIUM
CVE-2022-39166
all versions
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force I
4.4MEDIUM
CVE-2021-39077
>= 11.0 and <= 11.4
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read b
4.4MEDIUM
CVE-2021-39074
all versions
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
6.1MEDIUM
CVE-2021-39078
all versions
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force I
4.4MEDIUM
CVE-2021-39076
all versions
IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sen
7.5HIGH
CVE-2021-39072
all versions
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable
5.9MEDIUM
CVE-2021-29735
all versions
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows user
5.4MEDIUM
CVE-2021-20377
all versions
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
2.7LOW
CVE-2020-4690
all versions
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
9.8CRITICAL
CVE-2021-29773
all versions
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user det
5.4MEDIUM
CVE-2021-20433
all versions
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attac
6.5MEDIUM
CVE-2021-20427
all versions
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cr
7.5HIGH
CVE-2021-20420
all versions
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further atta
4.3MEDIUM
CVE-2021-20418
all versions
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attacker
9.8CRITICAL
CVE-2021-20557
all versions
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a sp
7.2HIGH
CVE-2021-20428
all versions
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
5.3MEDIUM
CVE-2021-20426
all versions
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
9.8CRITICAL
CVE-2021-20419
all versions
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi
7.5HIGH
CVE-2021-20389
all versions
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
7.8HIGH
CVE-2021-20386
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
6.1MEDIUM
CVE-2021-20385
all versions
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
7.2HIGH
CVE-2020-4990
all versions
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which co
8.8HIGH
CVE-2020-4184
all versions
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which create
7.3HIGH
CVE-2020-4952
all versions
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 1
8.8HIGH
CVE-2020-4189
all versions
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against t
4.3MEDIUM
CVE-2020-4921
all versions
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements,
8.8HIGH
CVE-2020-4688
all versions
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged us
7.8HIGH
CVE-2020-4689
all versions
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the sy
6.8MEDIUM
CVE-2020-4681
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
5.4MEDIUM
CVE-2020-4680
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
5.4MEDIUM
CVE-2020-4679
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
4.8MEDIUM
CVE-2020-4678
all versions
IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have ac
4.9MEDIUM
CVE-2018-1501
all versions
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing securit
7.5HIGH
CVE-2020-4186
all versions
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attack
5.3MEDIUM
CVE-2020-4185
all versions
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decr
7.5HIGH
CVE-2020-4188
all versions
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredic
5.3MEDIUM
CVE-2020-4193
all versions
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cr
9.8CRITICAL
CVE-2020-4191
all versions
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi
4.4MEDIUM
CVE-2020-4183
all versions
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
6.1MEDIUM
CVE-2020-4307
all versions
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of
6.5MEDIUM
CVE-2020-4190
all versions
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses
6.7MEDIUM
CVE-2020-4187
all versions
IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the sy
5.3MEDIUM
CVE-2020-4182
all versions
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
6.1MEDIUM
CVE-2020-4180
all versions
IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
8.8HIGH
CVE-2020-4177
all versions
IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
9.8CRITICAL
CVE-2019-4422
>= 9.0 and <= 9.5
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to chang
8.8HIGH
CVE-2019-4292
all versions
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbi
8.8HIGH
CVE-2018-1891
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
5.4MEDIUM
CVE-2018-1889
>= 10.0 and <= 10.5
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
5.4MEDIUM
CVE-2017-1597
>= 10.0 and <= 10.5
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users s
5.9MEDIUM
CVE-2017-1272
>= 10.0 and <= 10.5
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if una
3.7LOW
CVE-2017-1265
>= 10.0 and <= 10.5
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certific
3.7LOW
CVE-2018-1818
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its
5.9MEDIUM
CVE-2018-1817
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
6.1MEDIUM
CVE-2017-1268
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a pass
5.9MEDIUM
CVE-2018-1509
all versions
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attac
3.7LOW
CVE-2018-1498
all versions
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force
6.2MEDIUM
CVE-2017-1255
all versions
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an
7.5HIGH
CVE-2017-1757
all versions
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co
8.8HIGH
CVE-2017-1600
all versions
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to emb
5.4MEDIUM
CVE-2017-1598
all versions
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attack
7.5HIGH
CVE-2017-1596
all versions
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspe
5.5MEDIUM
CVE-2017-1595
all versions
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspe
5.5MEDIUM
CVE-2017-1270
all versions
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixatio
3.3LOW
CVE-2017-1266
all versions
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or
5.4MEDIUM
CVE-2017-1262
all versions
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability us
6.1MEDIUM
CVE-2017-1261
all versions
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force I
3.3LOW
CVE-2017-1257
all versions
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further att
4.3MEDIUM
CVE-2017-1271
all versions
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which al
7.5HIGH
CVE-2017-1267
all versions
IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin a
7.5HIGH
CVE-2017-1264
all versions
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure
7.5HIGH
CVE-2017-1254
all versions
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack
7.1HIGH
CVE-2017-1253
all versions
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
9.9CRITICAL
CVE-2017-1269
all versions
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements,
9.8CRITICAL
CVE-2017-1258
all versions
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing ano
6.5MEDIUM
CVE-2017-1256
all versions
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr
6.1MEDIUM
CVE-2016-0238
all versions
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could
3.7LOW
CVE-2017-1122
all versions
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbi
7.4HIGH
CVE-2016-6065
all versions
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as ro
7.8HIGH
CVE-2016-0247
all versions
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain
7.8HIGH
CVE-2016-0246
all versions
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 1
6.1MEDIUM
CVE-2016-0242
all versions
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading a
4.3MEDIUM
CVE-2016-0249
<= 8.2
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 1
8.6HIGH
CVE-2016-0248
all versions
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string inf
3.7LOW
CVE-2016-0298
<= 10.0
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticate
6.5MEDIUM
CVE-2015-5043
all versions
diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain roo
threatengine.sh