PT-2020-7213 · Ibm · Ibm Infosphere Guardium
Published
2020-09-01
·
Updated
2020-09-04
·
CVE-2012-3336
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Guardium versions 8.0 through 8.2
Description
The issue allows a remote authenticated attacker to send specially-crafted SQL statements to multiple scripts. This could enable the attacker to view, add, modify, or delete information in the back-end database.
Recommendations
For IBM InfoSphere Guardium versions 8.0 through 8.2, consider restricting access to the database and limiting the privileges of authenticated users to minimize the risk of exploitation. As a temporary workaround, consider disabling the scripts that are vulnerable to SQL injection until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Infosphere Guardium