Security Guardium

Vendor:

First CVE: Nov 8, 2015 · Active for 10 years

112
Total CVEs
More Total CVEs than 99% of tracked products
10.2
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Guardium over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2015
10 years ago
Most Recent CVE
May 28, 2025
425 days ago

CVE Severity & Scoring

Security Guardium112 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local18 (16.1%)
Network92 (82.1%)
Unknown1 (0.9%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low105 (93.8%)
High6 (5.4%)
Unknown1 (0.9%)
User Interaction
None90 (80.4%)
Unknown1 (0.9%)
Required21 (18.8%)
Privileges Required
Low50 (44.6%)
High14 (12.5%)
None47 (42.0%)
Unknown1 (0.9%)

Top CVEs

Signals from CVEs in this product scope (112 CVEs).

112 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
Jun 4, 20209.831NONO
IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication
Dec 13, 20189.831NONO
IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploi
Jul 5, 20179.930NONO
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to ext
Sep 23, 20219.829NONO
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196
Aug 11, 20219.829NONO
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to ext
May 24, 20219.829NONO
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.
Oct 3, 20198.828NONO
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modi
Jan 20, 20218.827NONO
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-For
Jul 2, 20198.827NONO
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IB
May 14, 20248.826NONO

Exploit Exposure

Signals from CVEs in this product scope (112 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (112 CVEs).

Media Mentions

Signals from CVEs in this product scope (112 CVEs).

Top CNAs Publishing CVEs For Security Guardium

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.597.10.8%00
9.197.10.8%00
9.0106.70.8%00
8.257.30.4%00
12.0106.00.4%00
11.5146.80.5%00
11.4176.70.6%00
11.3206.80.7%00
11.2226.91.1%00
11.1136.70.9%00
11.036.50.6%00
10.6136.80.9%00
10.5106.60.9%00
10.1.417.51.1%00
10.1.3115.70.7%00
10.1.2206.51.0%00
10.1.0115.80.8%00
10.1147.11.1%00
10.0.1206.71.0%00
10.0136.10.6%00