CVE-2023-35893 – IBM Security Guardium command execution
https://notcve.org/view.php?id=CVE-2023-35893
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. • https://exchange.xforce.ibmcloud.com/vulnerabilities/258824 https://www.ibm.com/support/pages/node/7027853 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-22307 – IBM Security Guardium privilege escalation
https://notcve.org/view.php?id=CVE-2022-22307
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. IBM Security Guardium v11.3, v11.4 y v11.5 podría permitir a un usuario local obtener privilegios elevados debido a comprobaciones de autorización incorrectas. ID de IBM X-Force: 216753. • https://exchange.xforce.ibmcloud.com/vulnerabilities/216753 https://www.ibm.com/support/pages/node/6999317 • CWE-863: Incorrect Authorization •
CVE-2023-0041 – IBM Security Guardium session fixation
https://notcve.org/view.php?id=CVE-2023-0041
IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657. IBM Security Guardium v11.5 podría permitir a un usuario tomar el control de la sesión de otro usuario debido a una caducidad de sesión insuficiente. IBM X-Force ID: 243657. • https://exchange.xforce.ibmcloud.com/vulnerabilities/243657 https://www.ibm.com/support/pages/node/7000021 • CWE-613: Insufficient Session Expiration •