CVE-2022-43903 – IBM Security Guardium denial of service
https://notcve.org/view.php?id=CVE-2022-43903
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894. IBM Security Guardium v10.6, v11.3 y v11.4 podría permitir a un usuario autenticado provocar una denegación de servicio debido a una validación de entrada incorrecta. IBM X-Force ID: 240894. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240894 https://www.ibm.com/support/pages/node/7030110 • CWE-20: Improper Input Validation •
CVE-2022-43904 – IBM Security Guardium information disclosure
https://notcve.org/view.php?id=CVE-2022-43904
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895. IBM Security Guardium 11.3 y 11.4 podría revelar información confidencial a un atacante debido a la restricción inadecuada de intentos de autenticación excesivos. ID de IBM X-Force: 240895. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240895 https://https://www.ibm.com/support/pages/node/7028509 • CWE-307: Improper Restriction of Excessive Authentication Attempts •
CVE-2023-33852 – IBM Security Guardium SQL injection
https://notcve.org/view.php?id=CVE-2023-33852
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614. IBM Security Guardium v11.4 es vulnerable a la inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente manipuladas, lo que podría permitir al atacante ver, añadir, modificar o eliminar información en la base de datos del back-end. • https://exchange.xforce.ibmcloud.com/vulnerabilities/257614 https://www.ibm.com/support/pages/node/7028514 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43909 – IBM Security Guardium cross-site scripting
https://notcve.org/view.php?id=CVE-2022-43909
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905. IBM Security Guardium v11.4 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera la funcionalidad prevista y puede conducir a la divulgación de credenciales en una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240905 https://www.ibm.com/support/pages/node/7028511 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43907 – IBM Security Guardium command execution
https://notcve.org/view.php?id=CVE-2022-43907
IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901. IBM Security Guardium 11.4 podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema enviando una solicitud especialmente manipulada. ID de IBM X-Force: 240901. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240901 https://www.ibm.com/support/pages/node/7028511 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •