CVE-2020-4952
https://notcve.org/view.php?id=CVE-2020-4952
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028. IBM Security Guardium versión 11.2, podría permitir a un usuario autenticado conseguir acceso root debido a un control de acceso inapropiado. IBM X-Force ID: 192028 • https://exchange.xforce.ibmcloud.com/vulnerabilities/192028 https://www.ibm.com/support/pages/node/6408630 •
CVE-2020-4189
https://notcve.org/view.php?id=CVE-2020-4189
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system. IBM X-Force ID: 174850. IBM Security Guardium versión 11.2, divulga información confidencial en los encabezados de respuesta que podría ser usada en futuros ataques contra el sistema. IBM X-Force ID: 174850 • https://exchange.xforce.ibmcloud.com/vulnerabilities/174850 https://www.ibm.com/support/pages/node/6408634 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2020-4921
https://notcve.org/view.php?id=CVE-2020-4921
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398. IBM Security Guardium versiones 10.6 y 11.2, es vulnerable a una inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, lo que podría permitir al atacante visualizar, agregar, modificar o eliminar información en la base de datos del back-end. • https://exchange.xforce.ibmcloud.com/vulnerabilities/191398 https://www.ibm.com/support/pages/node/6405952 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-4688
https://notcve.org/view.php?id=CVE-2020-4688
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700. IBM Security Guardium versiones 10.6 y 11.2, podrían permitir a un atacante local ejecutar comandos arbitrarios en el sistema como un usuario sin privilegios, causado por una vulnerabilidad de inyección de comandos. IBM X-Force ID: 186700 • https://exchange.xforce.ibmcloud.com/vulnerabilities/186700 https://www.ibm.com/support/pages/node/6405952 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2020-4689
https://notcve.org/view.php?id=CVE-2020-4689
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696. IBM Security Guardium versión 11.2, es vulnerable a una Inyección CVS. Un atacante privilegiado remoto podría ejecutar comandos arbitrarios en el sistema, causados por una comprobación inapropiada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/186696 https://www.ibm.com/support/pages/node/6346884 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •