Vulnerabilities > IBM > Guardium Cloud KEY Manager

DATE CVE VULNERABILITY TITLE RISK
2023-08-28 CVE-2023-26270 Cross-site Scripting vulnerability in IBM Guardium Cloud KEY Manager
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw.
network
low complexity
ibm CWE-79
critical
9.8
2023-08-28 CVE-2023-26271 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Guardium Cloud KEY Manager
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
7.5
2023-08-28 CVE-2023-26272 Information Exposure Through an Error Message vulnerability in IBM Guardium Cloud KEY Manager
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.3