4 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

28 May 2025 — IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input. • https://www.ibm.com/support/pages/node/7234827 • CWE-116: Improper Encoding or Escaping of Output •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

28 May 2025 — IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check. • https://www.ibm.com/support/pages/node/7234827 • CWE-863: Incorrect Authorization •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

28 May 2025 — IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. • https://www.ibm.com/support/pages/node/7234827 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

16 May 2024 — IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690. IBM Security Guardium 12.0 podría permitir que un usuario privilegiado realice acciones no autorizadas que podrían provocar una denegación de servicio. ID de IBM X-Force: 271690. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271690 • CWE-770: Allocation of Resources Without Limits or Throttling •