CVE-2025-3440: IBM Security Guardium cross-site scripting
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Security Guardium is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3440?
CVE-2025-3440 has a moderate severity rating due to its potential for credential disclosure through stored cross-site scripting.
How do I fix CVE-2025-3440?
To fix CVE-2025-3440, upgrade your IBM Security Guardium to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-3440?
CVE-2025-3440 affects users of IBM Security Guardium 11.5, particularly those with privileged access to the web interface.
What kind of attack is CVE-2025-3440 associated with?
CVE-2025-3440 is associated with stored cross-site scripting attacks, allowing attackers to inject arbitrary JavaScript into the web interface.
Can CVE-2025-3440 lead to data breaches?
Yes, CVE-2025-3440 can potentially lead to data breaches by allowing the disclosure of credentials within trusted sessions.