Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Security Guardium
Total 106 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1498 1 Ibm 1 Security Guardium 2024-11-21 2.1 LOW 6.2 MEDIUM
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.
CVE-2017-1597 1 Ibm 1 Security Guardium 2024-11-21 5.0 MEDIUM 5.9 MEDIUM
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
CVE-2017-1272 1 Ibm 1 Security Guardium 2024-11-21 5.0 MEDIUM 3.7 LOW
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 124747. IBM X-Force ID: 124747.
CVE-2017-1268 1 Ibm 1 Security Guardium 2024-11-21 2.1 LOW 5.9 MEDIUM
IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 124743.
CVE-2017-1265 1 Ibm 1 Security Guardium 2024-11-21 4.3 MEDIUM 3.7 LOW
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) techniques. IBM X-Force ID: 124740.
CVE-2017-1255 1 Ibm 1 Security Guardium 2024-11-21 5.0 MEDIUM 7.5 HIGH
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 124675.