Security Guardium Database Activity Monitor

Vendor:

First CVE: Oct 21, 2016 · Active for 9 years

9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Guardium Database Activity Monitor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2016
9 years ago
Most Recent CVE
May 2, 2018
3,009 days ago

CVE Severity & Scoring

Security Guardium Database Activity Monitor9 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local4 (44.4%)
Network5 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (66.7%)
High1 (11.1%)
None2 (22.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for
May 2, 20189.830NONO
IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB
Mar 12, 20188.226NONO
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administr
Oct 22, 20168.822NONO
IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with adminis
Oct 22, 20168.822NONO
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitra
Oct 21, 20168.822NONO
IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328.
Mar 12, 20185.520NONO
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privilege
Oct 22, 20167.820NONO
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin shou
Feb 9, 20184.417NONO
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which
Oct 22, 20163.713NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Security Guardium Database Activity Monitor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.567.01.2%00
9.167.01.2%00
9.067.01.2%00
8.247.31.5%00
10.1.419.82.5%00
10.1.319.82.5%00
10.1.219.82.5%00
10.157.81.7%00
10.0.129.31.9%00
10.0147.31.5%00
10.087.71.3%00