First published: Tue Aug 20 2019(Updated: )
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 161419.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Big Data Intelligence | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4340 is rated as critical due to its potential to expose sensitive information.
To fix CVE-2019-4340, it's recommended to update to the latest version of IBM Security Guardium Big Data Intelligence.
CVE-2019-4340 is associated with an XML External Entity Injection (XXE) attack.
A remote attacker exploiting CVE-2019-4340 could potentially expose sensitive information or consume memory resources.
Only IBM Security Guardium Big Data Intelligence version 4.0 is affected by CVE-2019-4340.