CVE-2020-4689: High severity ibm infosphere guardium z/os vulnerability
IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696.
Other sources
IBM Security Guardium is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4689?
CVE-2020-4689 is rated as high severity due to its potential for remote command execution by an attacker.
How do I fix CVE-2020-4689?
To remediate CVE-2020-4689, upgrade to a patched version of IBM Security Guardium that addresses the CVS Injection vulnerability.
What software versions are affected by CVE-2020-4689?
CVE-2020-4689 affects IBM Security Guardium versions 11.0 to 11.2.
Who can exploit CVE-2020-4689?
A remote privileged attacker can exploit CVE-2020-4689 to execute arbitrary commands on the affected system.
What is CVS Injection in the context of CVE-2020-4689?
CVS Injection refers to the improper validation of CSV file contents that allows an attacker to execute unauthorized commands.