Vulnerabilities > IBM > Security Guardium > Low

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-20377 Information Exposure Through an Error Message vulnerability in IBM Security Guardium 11.3
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
2.7
2017-12-20 CVE-2017-1261 Information Exposure vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-200
3.3
2017-12-20 CVE-2017-1270 Session Fixation vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability.
local
low complexity
ibm CWE-384
3.3
2017-07-05 CVE-2016-0238 Information Exposure vulnerability in IBM Security Guardium
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request.
network
high complexity
ibm CWE-200
3.7
2016-09-26 CVE-2016-0248 Information Exposure vulnerability in IBM Security Guardium 10.0/9.0
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
network
high complexity
ibm CWE-200
3.7