CVE-2020-4345: SQL Injection
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
Other sources
IBM i users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4345?
CVE-2020-4345 is rated as a medium severity vulnerability due to the potential for local users to access sensitive information improperly.
How do I fix CVE-2020-4345?
To mitigate CVE-2020-4345, users should apply the latest security patches provided by IBM for affected versions of the i operating system.
Who is affected by CVE-2020-4345?
CVE-2020-4345 affects IBM i 7.2, 7.3, and 7.4 systems where complex SQL statements are executed in certain circumstances.
What kind of information can be accessed due to CVE-2020-4345?
CVE-2020-4345 may allow local users to obtain sensitive information that they normally do not have access to.
Is CVE-2020-4345 a local or remote vulnerability?
CVE-2020-4345 is a local vulnerability that requires authenticated access to the affected systems.