CVE-2024-49336 – IBM Security Guardium server-side request forgery
https://notcve.org/view.php?id=CVE-2024-49336
IBM Security Guardium 11.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. • https://www.ibm.com/support/pages/node/7179369 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2023-42004 – IBM Security Guardium CSV injection
https://notcve.org/view.php?id=CVE-2023-42004
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262. IBM Security Guardium 11.3, 11.4 y 11.5 es potencialmente vulnerable a la inyección de CSV. Un atacante remoto podría ejecutar comandos maliciosos debido a una validación inadecuada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/265262 https://www.ibm.com/support/pages/node/7069241 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2022-43906 – IBM Security Guardium information disclosure
https://notcve.org/view.php?id=CVE-2022-43906
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897. IBM Security Guardium 11.5 podría revelar información confidencial debido a un atributo SameSite faltante o inseguro para una cookie confidencial. ID de IBM X-Force: 240897. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240897 https://https://www.ibm.com/support/pages/node/7038019 •
CVE-2023-30437 – IBM Security Guardium information disclosure
https://notcve.org/view.php?id=CVE-2023-30437
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293. IBM Security Guardium 11.3, 11.4 y 11.5 podría permitir a un usuario no autorizado enumerar nombres de usuario enviando una solicitud HTTP especialmente manipulada. ID de IBM X-Force: 252293. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252293 https://www.ibm.com/support/pages/node/7028506 •
CVE-2023-30436 – IBM Security Guardium cross-site scripting
https://notcve.org/view.php?id=CVE-2023-30436
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292. IBM Security Guardium 11.3, 11.4 y 11.5 es vulnerable a Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los usuarios incrustar código JavaScript arbitrario en la interfaz de usuario web, lo que altera la funcionalidad prevista y puede conducir a la divulgación de credenciales en una sesión de confianza. • https://exchange.xforce.ibmcloud.com/vulnerabilities/252292 https://www.ibm.com/support/pages/node/7028506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •