Vulnerabilities > IBM > Security Guardium

DATE CVE VULNERABILITY TITLE RISK
2021-01-20 CVE-2020-4921 SQL Injection vulnerability in IBM Security Guardium 10.6/11.2
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2021-01-20 CVE-2020-4688 Command Injection vulnerability in IBM Security Guardium 10.6/11.2
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability.
local
low complexity
ibm CWE-77
7.8
2020-10-12 CVE-2020-4689 Improper Neutralization of Formula Elements in a CSV File vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to CVS Injection.
network
low complexity
ibm CWE-1236
6.8
2020-10-12 CVE-2020-4681 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-12 CVE-2020-4680 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2020-10-12 CVE-2020-4679 Cross-site Scripting vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
4.8
2020-10-12 CVE-2020-4678 Unspecified vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to.
network
low complexity
ibm
4.9
2020-08-26 CVE-2018-1501 Missing Authentication for Critical Function vulnerability in IBM Security Guardium 10.5/10.6/11.0
IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missing security controls.
network
low complexity
ibm CWE-306
7.5
2020-07-30 CVE-2020-4186 Information Exposure vulnerability in IBM Security Guardium 10.5/10.6/11.1
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system.
network
low complexity
ibm CWE-200
5.3
2020-07-30 CVE-2020-4185 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Security Guardium 10.5/10.6/11.1
IBM Security Guardium 10.5, 10.6, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-327
7.5