First published: Wed Jul 05 2017(Updated: )
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =10.0 | |
IBM InfoSphere Guardium z/OS | =10.0.1 | |
IBM InfoSphere Guardium z/OS | =10.1 | |
IBM InfoSphere Guardium z/OS | =10.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1269 is classified as a critical vulnerability due to its potential for remote exploitation through SQL injection.
To fix CVE-2017-1269, it is recommended to upgrade IBM Security Guardium to versions 10.1.2 or later where the vulnerability has been addressed.
CVE-2017-1269 affects IBM Security Guardium versions 10.0, 10.0.1, and 10.1.
Exploitation of CVE-2017-1269 can allow attackers to view, add, modify, or delete information in the back-end database.
CVE-2017-1269 is a remote vulnerability, allowing attackers to exploit it without physical access to the system.