IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
| Software | From | Fixed in |
|---|---|---|
| ibm / security_guardium | 10.5 | 10.5.x |
| ibm / security_guardium | 10.6 | 10.6.x |
| ibm / security_guardium | 11.0 | 11.0.x |
| ibm / security_guardium | 11.1 | 11.1.x |
| ibm / security_guardium | 11.2 | 11.2.x |
| ibm / security_guardium | 11.3 | 11.3.x |