First published: Fri May 15 2020(Updated: )
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | <=7.4 | |
IBM OS/400 | <=7.3 | |
IBM OS/400 | <=7.2 | |
IBM OS/400 | =7.2 | |
IBM OS/400 | =7.3 | |
IBM OS/400 | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4345 is rated as a medium severity vulnerability due to the potential for local users to access sensitive information improperly.
To mitigate CVE-2020-4345, users should apply the latest security patches provided by IBM for affected versions of the i operating system.
CVE-2020-4345 affects IBM i 7.2, 7.3, and 7.4 systems where complex SQL statements are executed in certain circumstances.
CVE-2020-4345 may allow local users to obtain sensitive information that they normally do not have access to.
CVE-2020-4345 is a local vulnerability that requires authenticated access to the affected systems.