Page 30 of 182 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778. IBM Security Guardium Big Data Intelligence (SonarG) 3.1 almacena las credenciales de usuario en formato de texto plano, por lo que podrían ser leídos por un usuario local. IBM X-Force ID: 137778. • http://www.ibm.com/support/docview.wss?uid=swg22013596 http://www.securityfocus.com/bid/103213 https://exchange.xforce.ibmcloud.com/vulnerabilities/137778 • CWE-522: Insufficiently Protected Credentials •

CVSS: 4.4EPSS: 0%CPEs: 3EXPL: 0

IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765. IBM Security Guardium Database Activity Monitor 9.0, 9.1 y 9.5 podría permitir que un usuario local con pocos privilegios vea páginas de reporte y realice algunas acciones que solo deberían estar permitidas para un administrador. Por lo tanto, existe el riesgo de que alguien no autorizado cambie cosas para las que no debería tener permiso. IBM X-Force ID: 137765. • http://www.ibm.com/support/docview.wss?uid=swg22013302 http://www.securitytracker.com/id/1040349 https://exchange.xforce.ibmcloud.com/vulnerabilities/137765 • CWE-269: Improper Privilege Management •

CVSS: 3.3EPSS: 0%CPEs: 5EXPL: 0

IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736. IBM Security Guardium 10.0 almacena información potencialmente sensible en archivos de registro que pueden ser leídos por un usuario local. IBM X-Force ID: 124736. • http://www.ibm.com/support/docview.wss?uid=swg22010437 https://exchange.xforce.ibmcloud.com/vulnerabilities/124736 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 5EXPL: 0

IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737. IBM Security Guardium 10.0 es vulnerable a ataques de separación de respuesta HTTP. • http://www.ibm.com/support/docview.wss?uid=swg22010438 https://exchange.xforce.ibmcloud.com/vulnerabilities/124737 • CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741. IBM Security Guardium 10.0 especifica permisos para un recurso crítico para la seguridad de forma que permite que ese recurso sea leído o modificado por actores no planeados. IBM X-Force ID: 124741. • http://www.ibm.com/support/docview.wss?uid=swg22011516 https://exchange.xforce.ibmcloud.com/vulnerabilities/124741 • CWE-732: Incorrect Permission Assignment for Critical Resource •