IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/6346884 | Patch Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/186696 | VDB Entry |
Configurations
Information
Published : 2020-10-12 14:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-4689
Mitre link : CVE-2020-4689
JSON object : View
Products Affected
ibm
- security_guardium
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
