Vulnerabilities > IBM > Security Guardium > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-04 CVE-2022-43906 Unspecified vulnerability in IBM Security Guardium 11.5
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
network
low complexity
ibm
5.3
2023-09-05 CVE-2022-43903 Unspecified vulnerability in IBM Security Guardium 10.6/11.3/11.4
IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation.
network
low complexity
ibm
6.5
2023-08-27 CVE-2022-43909 Cross-site Scripting vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-08-27 CVE-2023-30435 Cross-site Scripting vulnerability in IBM Security Guardium 11.3/11.4/11.5
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-08-27 CVE-2023-30436 Cross-site Scripting vulnerability in IBM Security Guardium 11.3/11.4/11.5
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-08-27 CVE-2023-30437 Unspecified vulnerability in IBM Security Guardium 11.3/11.4/11.5
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request.
network
low complexity
ibm
5.3
2023-08-27 CVE-2023-33852 SQL Injection vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
5.4
2023-07-19 CVE-2022-43908 Improper Input Validation vulnerability in IBM Security Guardium 11.3
IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation.
network
low complexity
ibm CWE-20
6.5
2022-12-20 CVE-2022-39166 Unspecified vulnerability in IBM Security Guardium 11.4
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response.
network
low complexity
ibm
4.9
2022-11-03 CVE-2021-39077 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user.
local
low complexity
ibm CWE-312
4.4