Product
ibm security guardium
112 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-25029
CVE-2025-25026
CVE-2025-25025
CVE-2025-3440
CVE-2025-25023
CVE-2024-49336
CVE-2023-47710
CVE-2023-47717
CVE-2023-47712
CVE-2023-47711
CVE-2023-47709
CVE-2023-42004
CVE-2022-43906
CVE-2022-43903
CVE-2022-43904
CVE-2023-33852
CVE-2023-30437
CVE-2023-30436
CVE-2023-30435
CVE-2022-43909
CVE-2022-43907
CVE-2023-35893
CVE-2022-43910
CVE-2022-43908
CVE-2022-22307
CVE-2023-0041
CVE-2022-39166
CVE-2021-39077
CVE-2021-39074
CVE-2021-39078
CVE-2021-39076
CVE-2021-39072
CVE-2021-29735
CVE-2021-20377
CVE-2020-4690
CVE-2021-29773
CVE-2021-20433
CVE-2021-20427
CVE-2021-20420
CVE-2021-20418
CVE-2021-20557
CVE-2021-20428
CVE-2021-20426
CVE-2021-20419
CVE-2021-20389
CVE-2021-20386
CVE-2021-20385
CVE-2020-4990
CVE-2020-4184
CVE-2020-4952
CVE-2020-4189
CVE-2020-4921
CVE-2020-4688
CVE-2020-4689
CVE-2020-4681
CVE-2020-4680
CVE-2020-4679
CVE-2020-4678
CVE-2018-1501
CVE-2020-4186
CVE-2020-4185
CVE-2020-4188
CVE-2020-4193
CVE-2020-4191
CVE-2020-4183
CVE-2020-4307
CVE-2020-4190
CVE-2020-4187
CVE-2020-4182
CVE-2020-4180
CVE-2020-4177
CVE-2019-4422
CVE-2019-4292
CVE-2018-1891
CVE-2018-1889
CVE-2017-1597
CVE-2017-1272
CVE-2017-1265
CVE-2018-1818
CVE-2018-1817
CVE-2017-1268
CVE-2018-1509
CVE-2018-1498
CVE-2017-1255
CVE-2017-1757
CVE-2017-1600
CVE-2017-1598
CVE-2017-1596
CVE-2017-1595
CVE-2017-1270
CVE-2017-1266
CVE-2017-1262
CVE-2017-1261
CVE-2017-1257
CVE-2017-1271
CVE-2017-1267
CVE-2017-1264
CVE-2017-1254
CVE-2017-1253
CVE-2017-1269
CVE-2017-1258
CVE-2017-1256
CVE-2016-0238
CVE-2017-1122
CVE-2016-6065
CVE-2016-0247
CVE-2016-0246
CVE-2016-0242
CVE-2016-0249
CVE-2016-0248
CVE-2016-0298
CVE-2015-5043
all versions
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
all versions
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication ch
all versions
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
all versions
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbi
>= 11.4 and <= 12.1
IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assign
all versions
IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker
all versions
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
all versions
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service.
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to imprope
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of se
all versions
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious
all versions
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive co
all versions
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper i
all versions
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive a
all versions
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which co
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed
all versions
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a sp
all versions
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the
all versions
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force
all versions
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-
all versions
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization c
all versions
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-F
all versions
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IBM X-Force I
>= 11.0 and <= 11.4
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read b
all versions
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force I
all versions
IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sen
all versions
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable
all versions
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows user
all versions
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
all versions
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
all versions
IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user det
all versions
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attac
all versions
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cr
all versions
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further atta
all versions
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attacker
all versions
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a sp
all versions
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message i
all versions
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
all versions
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi
all versions
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
all versions
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which co
all versions
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which create
all versions
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 1
all versions
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against t
all versions
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements,
all versions
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged us
all versions
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the sy
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have ac
all versions
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing securit
all versions
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attack
all versions
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decr
all versions
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredic
all versions
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cr
all versions
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi
all versions
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of
all versions
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses
all versions
IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the sy
all versions
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript co
all versions
IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
all versions
IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb
>= 9.0 and <= 9.5
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to chang
all versions
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbi
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
>= 10.0 and <= 10.5
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java
>= 10.0 and <= 10.5
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users s
>= 10.0 and <= 10.5
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if una
>= 10.0 and <= 10.5
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certific
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc
>= 10.0 and <= 10.5
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a pass
all versions
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attac
all versions
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force
all versions
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an
all versions
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co
all versions
IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows users to emb
all versions
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attack
all versions
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspe
all versions
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspe
all versions
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixatio
all versions
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or
all versions
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability us
all versions
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force I
all versions
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further att
all versions
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which al
all versions
IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin a
all versions
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure
all versions
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack
all versions
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a s
all versions
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements,
all versions
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing ano
all versions
IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr
all versions
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could
all versions
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbi
all versions
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as ro
all versions
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain
all versions
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 1
all versions
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading a
<= 8.2
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 1
all versions
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string inf
<= 10.0
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticate
all versions
diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain roo