PT-2021-3156 · Ibm · Ibm Security Guardium

Published

2021-05-21

·

Updated

2021-05-25

·

CVE-2021-20385

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Security Guardium version 11.2
Description The issue allows a remote authenticated attacker to execute arbitrary commands on the system by sending a specially-crafted request. This could enable an attacker to exploit the vulnerability and execute arbitrary commands on the system, potentially impacting the confidentiality, integrity, and availability of protected information.
Recommendations For IBM Security Guardium version 11.2, consider restricting access to the system until a patch is available, and avoid using the system for sensitive operations. As a temporary workaround, consider disabling any functionality that allows remote authenticated attackers to send specially-crafted requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02826
CVE-2021-20385

Affected Products

Ibm Security Guardium