PT-2020-7213 · Ibm · Ibm Infosphere Guardium

Published

2020-09-01

·

Updated

2020-09-04

·

CVE-2012-3336

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Guardium versions 8.0 through 8.2
Description The issue allows a remote authenticated attacker to send specially-crafted SQL statements to multiple scripts. This could enable the attacker to view, add, modify, or delete information in the back-end database.
Recommendations For IBM InfoSphere Guardium versions 8.0 through 8.2, consider restricting access to the database and limiting the privileges of authenticated users to minimize the risk of exploitation. As a temporary workaround, consider disabling the scripts that are vulnerable to SQL injection until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3336

Affected Products

Ibm Infosphere Guardium