PT-2016-4105 · Ibm · Ibm Security Guardium Database Activity Monitor
Chris Shepherd
+6
·
Published
2016-10-21
·
Updated
2016-11-28
·
CVE-2016-0236
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Security Guardium Database Activity Monitor versions 8.2 before p310
IBM Security Guardium Database Activity Monitor versions 9.x through 9.5 before p700
IBM Security Guardium Database Activity Monitor versions 10.x through 10.1 before p100
Description
The issue allows remote authenticated users to execute arbitrary commands with root privileges via the search field.
Recommendations
For IBM Security Guardium Database Activity Monitor version 8.2, update to p310 or later.
For IBM Security Guardium Database Activity Monitor versions 9.x through 9.5, update to p700 or later.
For IBM Security Guardium Database Activity Monitor versions 10.x through 10.1, update to p100 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Guardium Database Activity Monitor