PT-2024-4805 · Ibm · Ibm Security Guardium

Ben Goodspeed

+8

·

Published

2024-05-11

·

Updated

2025-01-14

·

CVE-2023-47709

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IBM Security Guardium versions 11.3 through 12.0
Description: The issue allows a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. This is due to the failure to neutralize special elements used in the operating system command. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For IBM Security Guardium versions 11.3 through 12.0, upgrade the affected component immediately to prevent potential system takeover. As a temporary workaround, consider restricting access to the request handler to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05329
CVE-2023-47709

Affected Products

Ibm Security Guardium