First published: Wed Aug 23 2023(Updated: )
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium | =11.3 | |
IBM Security Guardium | =11.4 | |
IBM Security Guardium | =11.5 | |
<=11.3 | ||
<=11.4 | ||
<=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-30437 is medium with a CVSS score of 5.3.
CVE-2023-30437 affects IBM Security Guardium versions 11.3, 11.4, and 11.5.
The vulnerability in IBM Security Guardium is the ability for an unauthorized user to enumerate usernames by sending a specially crafted HTTP request.
An unauthorized user can exploit CVE-2023-30437 by sending a specially crafted HTTP request to the affected IBM Security Guardium versions.
Yes, IBM has provided a fix for CVE-2023-30437. Please refer to the IBM Security Guardium support pages for more information.