Lucene search

K
ibmIBM804CAACAE9603898C84835C6F87A4B449B8C38D5C40D85A8068F70C2558749BD
HistoryJun 16, 2018 - 10:05 p.m.

Security Bulletin: IBM Security Guardium Database Activity Monitor is affected by Insufficient Authorization Checks vulnerability (CVE-2018-1368 )

2018-06-1622:05:26
www.ibm.com
7

0.0004 Low

EPSS

Percentile

5.1%

Summary

IBM Security Guardium Database Activity Monitor has addressed the following vulnerability

Vulnerability Details

CVEID: CVE-2018-1368**
DESCRIPTION:** IBM Security Guardium Database Activity Monitor could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to.
CVSS Base Score: 5.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/137765 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

IBM Security Guardium V9.0, 9.1, 9.5

IBM Security Guardium V10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM Security Guardium
Database Activity Monitor | 9.0-9.5| https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=IBM%2BSecurity&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard-9.0p758_Bundle_Jan-31-2018_32-bit,SqlGuard-9.0p758_Bundle_Jan-31-2018_64-bit&includeSupersedes=0&source=fc
IBM Security Guardium
Database Activity Monitor | 10.0-10.1.4| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%2BSecurity&product=ibm/Information+Management/InfoSphere+Guardium&release=All&platform=All&function=fixId&fixids=SqlGuard_10.0p402_Bundle_Feb-19-2018&includeSupersedes=0&source=fc

Workarounds and Mitigations

None

0.0004 Low

EPSS

Percentile

5.1%

Related for 804CAACAE9603898C84835C6F87A4B449B8C38D5C40D85A8068F70C2558749BD