PT-2024-4805 · Ibm · Ibm Security Guardium
Ben Goodspeed
+8
·
Published
2024-05-11
·
Updated
2025-01-14
·
CVE-2023-47709
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IBM Security Guardium versions 11.3 through 12.0
Description:
The issue allows a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. This is due to the failure to neutralize special elements used in the operating system command. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations:
For IBM Security Guardium versions 11.3 through 12.0, upgrade the affected component immediately to prevent potential system takeover. As a temporary workaround, consider restricting access to the request handler to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Guardium