First published: Sat Oct 22 2016(Updated: )
IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium Database Activity Monitoring | =9.0 | |
IBM InfoSphere Guardium Database Activity Monitoring | =9.1 | |
IBM InfoSphere Guardium Database Activity Monitoring | =9.5 | |
IBM InfoSphere Guardium Database Activity Monitoring | =10.0 | |
IBM InfoSphere Guardium Database Activity Monitoring | =10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0239 is considered critical due to the potential for remote authenticated users to escalate privileges.
To fix CVE-2016-0239, upgrade IBM Security Guardium Database Activity Monitor to version 9.5 p700 or 10.0.1 p100 or later.
CVE-2016-0239 affects IBM Security Guardium Database Activity Monitor versions 9.0, 9.1, 9.5, 10.0, and 10.0.1 before their respective patches.
Yes, CVE-2016-0239 can be exploited remotely by authenticated users with elevated privileges.
CVE-2016-0239 is a privilege escalation vulnerability that allows unauthorized HTTP requests with administrator permissions.