Vulnerabilities > IBM > Security Guardium > 11.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-27 | CVE-2023-30437 | Unspecified vulnerability in IBM Security Guardium 11.3/11.4/11.5 IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. | 5.3 |
2023-08-27 | CVE-2023-33852 | SQL Injection vulnerability in IBM Security Guardium 11.4 IBM Security Guardium 11.4 is vulnerable to SQL injection. | 5.4 |
2023-08-16 | CVE-2023-35893 | OS Command Injection vulnerability in IBM Security Guardium IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | 8.8 |
2023-06-15 | CVE-2022-22307 | Incorrect Authorization vulnerability in IBM Security Guardium 11.3/11.4/11.5 IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. | 7.8 |
2022-12-20 | CVE-2022-39166 | Unspecified vulnerability in IBM Security Guardium 11.4 IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. | 4.9 |
2022-11-03 | CVE-2021-39077 | Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. | 4.4 |
2022-06-29 | CVE-2021-39074 | Cross-site Scripting vulnerability in IBM Security Guardium 11.4 IBM Security Guardium 11.4 is vulnerable to cross-site scripting. | 6.1 |