CVE-2020-4165
https://notcve.org/view.php?id=CVE-2020-4165
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174401. IBM Security Guardium Insights versión 2.0.1, podría permitir a un atacante remoto secuestrar la acción de clic de la víctima. Al persuadir a una víctima para que visite un sitio web malicioso, un atacante remoto podría explotar esta vulnerabilidad para secuestrar las acciones de clic de la víctima y posiblemente iniciar nuevos ataques contra la víctima. • https://exchange.xforce.ibmcloud.com/vulnerabilities/174401 https://www.ibm.com/support/pages/node/6320069 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2020-4186
https://notcve.org/view.php?id=CVE-2020-4186
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174804. IBM Security Guardium versiones 10.5, 10.6 y 11.1, podría revelar información confidencial en la página de inicio de sesión que podría ayudar en nuevos ataques contra el sistema. IBM X-Force ID: 174804 • https://exchange.xforce.ibmcloud.com/vulnerabilities/174804 https://www.ibm.com/support/pages/node/6254367 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2020-4185
https://notcve.org/view.php?id=CVE-2020-4185
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174803. IBM Security Guardium versiones 10.5, 10.6 y 11.1, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 174803 • https://exchange.xforce.ibmcloud.com/vulnerabilities/174803 https://www.ibm.com/support/pages/node/6254369 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2020-4173
https://notcve.org/view.php?id=CVE-2020-4173
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 174682. IBM Guardium Activity Insights versiones 10.6 y 11.0, no establece el atributo seguro sobre los tokens de autorización o las cookies de sesión. • https://exchange.xforce.ibmcloud.com/vulnerabilities/174682 https://www.ibm.com/support/pages/node/6244924 •
CVE-2020-4188
https://notcve.org/view.php?id=CVE-2020-4188
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807. IBM Security Guardium versiones 10.6 y 11.1, puede utilizar números o valores insuficientemente aleatorios en un contexto de seguridad que depende de números impredecibles. IBM X-Force ID: 174807 • https://exchange.xforce.ibmcloud.com/vulnerabilities/174807 https://www.ibm.com/support/pages/node/6237074 • CWE-330: Use of Insufficiently Random Values •