CVE-2023-47706 – IBM Security Guardium Key Lifecycle Manager file upload
https://notcve.org/view.php?id=CVE-2023-47706
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. IBM Security Guardium Key Lifecycle Manager 4.3 podría permitir que un usuario autenticado cargue archivos de un tipo de archivo peligroso. ID de IBM X-Force: 271341. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271341 https://www.ibm.com/support/pages/node/7091157 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2023-47705 – IBM Security Guardium Key Lifecycle Manager improper input validation
https://notcve.org/view.php?id=CVE-2023-47705
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228. IBM Security Guardium Key Lifecycle Manager 4.3 podría permitir que un usuario autenticado manipule los datos del nombre de usuario debido a una validación de entrada incorrecta. ID de IBM X-Force: 271228. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271228 https://www.ibm.com/support/pages/node/7091157 • CWE-20: Improper Input Validation •
CVE-2023-47704 – IBM Security Guardium Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-47704
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220. IBM Security Guardium Key Lifecycle Manager 4.3 contiene credenciales codificadas en texto plano u otros secretos en el repositorio de código fuente. ID de IBM X-Force: 271220. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271220 https://www.ibm.com/support/pages/node/7091157 • CWE-798: Use of Hard-coded Credentials •
CVE-2023-42004 – IBM Security Guardium CSV injection
https://notcve.org/view.php?id=CVE-2023-42004
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. IBM Security Guardium 11.3, 11.4 y 11.5 es potencialmente vulnerable a la inyección de CSV. Un atacante remoto podría ejecutar comandos maliciosos debido a una validación inadecuada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/265262 https://www.ibm.com/support/pages/node/7069241 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2022-43906 – IBM Security Guardium information disclosure
https://notcve.org/view.php?id=CVE-2022-43906
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. IBM Security Guardium 11.5 podría revelar información confidencial debido a un atributo SameSite faltante o inseguro para una cookie confidencial. ID de IBM X-Force: 240897. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240897 https://https://www.ibm.com/support/pages/node/7038019 •