First published: Thu May 15 2025(Updated: )
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | ||
IBM Guardium Data Protection | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3440 has a moderate severity rating due to its potential for credential disclosure through stored cross-site scripting.
To fix CVE-2025-3440, upgrade your IBM Security Guardium to the latest version that addresses this vulnerability.
CVE-2025-3440 affects users of IBM Security Guardium 11.5, particularly those with privileged access to the web interface.
CVE-2025-3440 is associated with stored cross-site scripting attacks, allowing attackers to inject arbitrary JavaScript into the web interface.
Yes, CVE-2025-3440 can potentially lead to data breaches by allowing the disclosure of credentials within trusted sessions.