PT-2025-23045 · Ibm · Ibm Security Guardium

Published

2025-01-31

·

Updated

2025-06-04

·

CVE-2025-25025

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Guardium version 12.0
Description The issue allows a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Recommendations For IBM Security Guardium version 12.0, consider disabling the display of detailed technical error messages in the browser as a temporary workaround until a patch is available. Restrict access to sensitive system information to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-06320
CVE-2025-25025

Affected Products

Ibm Security Guardium