CVE-2023-30435 – IBM Security Guardium cross-site scripting
https://notcve.org/view.php?id=CVE-2023-30435
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291. IBM Security Guardium v11.3, v11.4 y v11.5 es vulnerable a Cross-Site Scripting (XSS) almacenado. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera la funcionalidad prevista y puede conducir a la divulgación de credenciales en una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252291 https://www.ibm.com/support/pages/node/7028506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-35893 – IBM Security Guardium command execution
https://notcve.org/view.php?id=CVE-2023-35893
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. • https://exchange.xforce.ibmcloud.com/vulnerabilities/258824 https://www.ibm.com/support/pages/node/7027853 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-43910 – IBM Security Guardium privilege escalation
https://notcve.org/view.php?id=CVE-2022-43910
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908. IBM Security Guardium v11.3 podría permitir a un usuario local escalar sus privilegios debido a controles de permisos inadecuados. ID de IBM X-Force: 240908. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240908 https://www.ibm.com/support/pages/node/7007815 • CWE-281: Improper Preservation of Permissions •
CVE-2022-43908 – IBM Security Guardium denial of service
https://notcve.org/view.php?id=CVE-2022-43908
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903. IBM Security Guardium v11.3 podría permitir a un usuario autenticado provocar una denegación de servicio debido a una incorrecta validación de entrada. ID de IBM X-Force: 240903. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240903 https://www.ibm.com/support/pages/node/7007815 • CWE-20: Improper Input Validation •
CVE-2022-22307 – IBM Security Guardium privilege escalation
https://notcve.org/view.php?id=CVE-2022-22307
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. IBM Security Guardium v11.3, v11.4 y v11.5 podría permitir a un usuario local obtener privilegios elevados debido a comprobaciones de autorización incorrectas. ID de IBM X-Force: 216753. • https://exchange.xforce.ibmcloud.com/vulnerabilities/216753 https://www.ibm.com/support/pages/node/6999317 • CWE-863: Incorrect Authorization •