Security Guardium Big Data Intelligence

Vendor:

First CVE: Feb 26, 2018 · Active for 8 years

22
Total CVEs
More Total CVEs than 95% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Guardium Big Data Intelligence over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2018
8 years ago
Most Recent CVE
Oct 16, 2020
2,110 days ago

CVE Severity & Scoring

Security Guardium Big Data Intelligence22 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local3 (13.6%)
Network19 (86.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None20 (90.9%)
Unknown0 (0.0%)
Required2 (9.1%)
Privileges Required
Low6 (27.3%)
High0 (0.0%)
None16 (72.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For
Mar 2, 20189.830NONO
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user
Feb 27, 20189.829NONO
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th
Aug 20, 20198.226NONO
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force
Oct 29, 20197.525NONO
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For
Aug 20, 20197.525NONO
IBM Security Guardium Big Data Intelligence 1.0 (SonarG) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IB
Oct 16, 20207.524NONO
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced by an actor. This weakness can
Aug 20, 20197.524NONO
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerab
May 29, 20187.524NONO
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IB
Oct 29, 20197.523NONO
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the mod
Oct 29, 20196.522NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Security Guardium Big Data Intelligence

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0116.31.2%00
3.1106.61.4%00
1.017.50.8%00