CVE-2017-1264

HIGH

IBM Security Guardium 10.0 - Improper Authentication

Title source: llm
STIX 2.1

Description

IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22004425
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99369

Scores

CVSS v3 7.5
EPSS 0.0153
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (8)
IBM/Security Guardium 10.0
IBM/Security Guardium 10.0.1
IBM/Security Guardium 10.1
IBM/Security Guardium 10.1.2
ibm/security_guardium 10.0
ibm/security_guardium 10.0.1
ibm/security_guardium 10.1
ibm/security_guardium 10.1.2
Published Jul 05, 2017
Tracked Since Feb 18, 2026