Vulnerabilities > IBM > Security Guardium

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-20557 OS Command Injection vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
7.2
2021-03-15 CVE-2020-4184 Improper Privilege Management vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
network
low complexity
ibm CWE-269
7.3
2021-01-27 CVE-2020-4952 Unspecified vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control.
network
low complexity
ibm
8.8
2021-01-27 CVE-2020-4189 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 discloses sensitive information in the response headers that could be used in further attacks against the system.
network
low complexity
ibm CWE-312
4.3
2021-01-20 CVE-2020-4921 SQL Injection vulnerability in IBM Security Guardium 10.6/11.2
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2021-01-20 CVE-2020-4688 Command Injection vulnerability in IBM Security Guardium 10.6/11.2
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability.
local
low complexity
ibm CWE-77
7.8
2020-10-12 CVE-2020-4689 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to CVS Injection.
network
low complexity
ibm CWE-1236
6.8
2020-10-12 CVE-2020-4681 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-12 CVE-2020-4680 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-12 CVE-2020-4679 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.8