9 results (0.014 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

15 May 2025 — IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. • https://www.ibm.com/support/pages/node/7233600 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

28 Nov 2023 — IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. IBM Security Guardium 11.3, 11.4 y 11.5 es potencialmente vulnerable a la inyección de CSV. Un atacante remoto podría ejecutar comandos maliciosos debido a una validación inadecuada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/265262 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

04 Oct 2023 — IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. IBM Security Guardium 11.5 podría revelar información confidencial debido a un atributo SameSite faltante o inseguro para una cookie confidencial. ID de IBM X-Force: 240897. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240897 •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

27 Aug 2023 — IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293. IBM Security Guardium 11.3, 11.4 y 11.5 podría permitir a un usuario no autorizado enumerar nombres de usuario enviando una solicitud HTTP especialmente manipulada. ID de IBM X-Force: 252293. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252293 •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

27 Aug 2023 — IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292. IBM Security Guardium 11.3, 11.4 y 11.5 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera l... • https://exchange.xforce.ibmcloud.com/vulnerabilities/252292 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.9EPSS: 0%CPEs: 3EXPL: 0

27 Aug 2023 — IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252291. IBM Security Guardium v11.3, v11.4 y v11.5 es vulnerable a Cross-Site Scripting (XSS) almacenado. Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario... • https://exchange.xforce.ibmcloud.com/vulnerabilities/252291 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.9EPSS: 0%CPEs: 5EXPL: 0

16 Aug 2023 — IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824. • https://exchange.xforce.ibmcloud.com/vulnerabilities/258824 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

15 Jun 2023 — IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753. IBM Security Guardium v11.3, v11.4 y v11.5 podría permitir a un usuario local obtener privilegios elevados debido a comprobaciones de autorización incorrectas. ID de IBM X-Force: 216753. • https://exchange.xforce.ibmcloud.com/vulnerabilities/216753 • CWE-863: Incorrect Authorization •

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

05 Jun 2023 — IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657. IBM Security Guardium v11.5 podría permitir a un usuario tomar el control de la sesión de otro usuario debido a una caducidad de sesión insuficiente. IBM X-Force ID: 243657. • https://exchange.xforce.ibmcloud.com/vulnerabilities/243657 • CWE-613: Insufficient Session Expiration •