First published: Tue Jan 05 2021(Updated: )
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium | =10.6 | |
IBM Security Guardium | =11.2 | |
Linux Linux kernel | ||
<=10.5 | ||
<=10.6 | ||
<=11.0 | ||
<=11.1 | ||
<=11.2 | ||
<=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4921.
The severity of CVE-2020-4921 is high, with a CVSS severity value of 8.8.
IBM Security Guardium versions 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 are affected by CVE-2020-4921.
CVE-2020-4921 allows remote attackers to execute SQL injection attacks on IBM Security Guardium, potentially gaining unauthorized access to or manipulating the back-end database.
Yes, you can find more information about CVE-2020-4921 on the IBM X-Force website (ID: 191398) and the IBM Support website.