PT-2021-3156 · Ibm · Ibm Security Guardium
Published
2021-05-21
·
Updated
2021-05-25
·
CVE-2021-20385
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Security Guardium version 11.2
Description
The issue allows a remote authenticated attacker to execute arbitrary commands on the system by sending a specially-crafted request. This could enable an attacker to exploit the vulnerability and execute arbitrary commands on the system, potentially impacting the confidentiality, integrity, and availability of protected information.
Recommendations
For IBM Security Guardium version 11.2, consider restricting access to the system until a patch is available, and avoid using the system for sensitive operations. As a temporary workaround, consider disabling any functionality that allows remote authenticated attackers to send specially-crafted requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Guardium