CVE-2018-1368: Medium severity ibm infosphere guardium database activity monitoring vulnerability
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1368?
CVE-2018-1368 is considered a medium severity vulnerability due to local privilege escalation risks.
How do I fix CVE-2018-1368?
To fix CVE-2018-1368, upgrade the IBM Security Guardium Database Activity Monitor to version 9.6 or later.
What versions of IBM Security Guardium are affected by CVE-2018-1368?
CVE-2018-1368 affects IBM Security Guardium Database Activity Monitor versions 9.0, 9.1, and 9.5.
Can a low privilege user exploit CVE-2018-1368?
Yes, a low privilege user can exploit CVE-2018-1368 to view administrative report pages and perform unauthorized actions.
Is there a risk associated with CVE-2018-1368?
Yes, there is a risk that unauthorized users could alter system settings and data due to the improper access afforded by CVE-2018-1368.