CVE-2025-25029: IBM Security Guardium information disclosure
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
Other sources
IBM Security Guardium could allow a privileged user to download any file on the system due to improper escaping of input.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25029?
CVE-2025-25029 has a high severity level due to the potential for privileged users to access sensitive files.
How do I fix CVE-2025-25029?
To mitigate CVE-2025-25029, apply the latest security updates provided by IBM for Security Guardium.
Who is affected by CVE-2025-25029?
CVE-2025-25029 affects users of IBM Security Guardium 12.0 who have privileged access.
What is the impact of CVE-2025-25029?
CVE-2025-25029 allows privileged users to download arbitrary files from the system, which could lead to data breaches.
Is there a workaround for CVE-2025-25029?
Currently, the recommended action is to upgrade to the patched version of IBM Security Guardium to resolve CVE-2025-25029.