Vulnerabilities > IBM > Security Guardium Insights

DATE CVE VULNERABILITY TITLE RISK
2020-08-24 CVE-2020-4593 Insufficiently Protected Credentials vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
4.4
2020-08-24 CVE-2020-4170 Cross-Site Request Forgery (CSRF) vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
4.3
2020-08-24 CVE-2020-4165 Improper Restriction of Rendered UI Layers or Frames vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-1021
5.4
2020-07-09 CVE-2020-4173 Unspecified vulnerability in IBM products
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm
4.3