Page 6 of 38 results (0.006 seconds)

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685 IBM Security Guardium 10.0 y 10.1 no lleva a cabo un chequeo de la autentificación para los recursos críticos o funcionalidades permitiendo a usuarios anónimos acceder a áreas protegidas. IBM X-Force ID: 124685 • http://www.ibm.com/support/docview.wss?uid=swg22004309 http://www.securityfocus.com/bid/99377 https://exchange.xforce.ibmcloud.com/vulnerabilities/124685 • CWE-287: Improper Authentication •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409 IBM Security Guardiam 9.0, 9.1, 9.5, 10.0 y 10.1 transmite información sensible en texto plano en la sentencia de la solicitud. Esto podría permitir a un atacante obtener información sensible utilizando la técnica Man-In-TheMiddle. IBM X-Force ID:110409. • http://www.ibm.com/support/docview.wss?uid=swg21989124 http://www.securityfocus.com/bid/99379 https://exchange.xforce.ibmcloud.com/vulnerabilities/110409 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678 IBM Security Guardium 10.0 y 10.1 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a usuarios incrustar código Javascript aleatorio en la interfaz web lo que alterará la funcionalidad planeada potencialmente llevando a la revelación de las credenciales dentro de una sesión confiable. IBM X-Force ID: 124678 • http://www.ibm.com/support/docview.wss?uid=swg22004461 http://www.securityfocus.com/bid/99376 https://exchange.xforce.ibmcloud.com/vulnerabilities/124678 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744 Security Guardium versiones 10.0 y 10.1 de IBM, es vulnerable a la inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente especialmente diseñadas, que podrían permitirle visualizar, agregar, modificar o eliminar información en la base de datos back-end. ID de IBM X-force: 124744 • http://www.ibm.com/support/docview.wss?uid=swg22004462 http://www.securityfocus.com/bid/99361 https://exchange.xforce.ibmcloud.com/vulnerabilities/124744 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.4EPSS: 0%CPEs: 8EXPL: 0

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174. IBM Security Guardium 8.2, 9.0 y 10.0 contiene una vulnerabilidad que podría permitir a un atacante local con acceso a CLI inyectar comandos arbitrarios que se ejecutarían como root. IBM X-Force ID: 121174. • http://www.ibm.com/support/docview.wss?uid=swg21997868 http://www.securityfocus.com/bid/97995 http://www.securitytracker.com/id/1038347 •