First published: Fri May 21 2021(Updated: )
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195767.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium | =11.2 | |
<=10.5 | ||
<=10.6 | ||
<=11.0 | ||
<=11.1 | ||
<=11.2 | ||
<=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the IBM Security Guardium vulnerability is CVE-2021-20386.
The severity of the IBM Security Guardium vulnerability is medium.
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
The vulnerability affects IBM Security Guardium versions up to and including 11.2.
To fix the vulnerability, update IBM Security Guardium to a version that is not affected by the vulnerability.