Vulnerabilities > IBM > Security Guardium > 11.4

DATE CVE VULNERABILITY TITLE RISK
2023-08-27 CVE-2023-30437 Unspecified vulnerability in IBM Security Guardium 11.3/11.4/11.5
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request.
network
low complexity
ibm
5.3
2023-08-27 CVE-2023-33852 SQL Injection vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
5.4
2023-08-16 CVE-2023-35893 OS Command Injection vulnerability in IBM Security Guardium
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
8.8
2023-06-15 CVE-2022-22307 Incorrect Authorization vulnerability in IBM Security Guardium 11.3/11.4/11.5
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks.
local
low complexity
ibm CWE-863
7.8
2022-12-20 CVE-2022-39166 Unspecified vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response.
network
low complexity
ibm
4.9
2022-11-03 CVE-2021-39077 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user.
local
low complexity
ibm CWE-312
4.4
2022-06-29 CVE-2021-39074 Cross-site Scripting vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1