CVE-2025-25025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7234827 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:security_guardium:12.0:*:*:*:*:*:*:*

History

04 Jun 2025, 14:34

Type Values Removed Values Added
First Time Ibm
Ibm security Guardium
CPE cpe:2.3:a:ibm:security_guardium:12.0:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7234827 - () https://www.ibm.com/support/pages/node/7234827 - Vendor Advisory

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) IBM Security Guardium 12.0 podría permitir que un atacante remoto obtenga información confidencial al recibir un mensaje de error técnico detallado en el navegador. Esta información podría utilizarse en futuros ataques contra el sistema.

28 May 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 02:15

Updated : 2025-06-04 14:34


NVD link : CVE-2025-25025

Mitre link : CVE-2025-25025

CVE.ORG link : CVE-2025-25025


JSON object : View

Products Affected

ibm

  • security_guardium
CWE
CWE-209

Generation of Error Message Containing Sensitive Information