CVE-2023-30437: IBM Security Guardium information disclosure
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
Other sources
IBM Security Guardium could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30437?
The severity of CVE-2023-30437 is medium with a CVSS score of 5.3.
How does CVE-2023-30437 affect IBM Security Guardium?
CVE-2023-30437 affects IBM Security Guardium versions 11.3, 11.4, and 11.5.
What is the vulnerability in IBM Security Guardium?
The vulnerability in IBM Security Guardium is the ability for an unauthorized user to enumerate usernames by sending a specially crafted HTTP request.
How can an unauthorized user exploit CVE-2023-30437?
An unauthorized user can exploit CVE-2023-30437 by sending a specially crafted HTTP request to the affected IBM Security Guardium versions.
Is there a fix available for CVE-2023-30437?
Yes, IBM has provided a fix for CVE-2023-30437. Please refer to the IBM Security Guardium support pages for more information.