CVE-2020-4990: SQL Injection
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
Other sources
IBM Security Guardium is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4990?
CVE-2020-4990 is classified as a critical vulnerability due to its potential for unauthorized database access through SQL injection.
How do I fix CVE-2020-4990?
To mitigate CVE-2020-4990, users should apply the security patches provided by IBM for versions up to 11.2 of IBM Security Guardium.
What types of attacks can exploit CVE-2020-4990?
CVE-2020-4990 can be exploited by remote attackers using specially crafted SQL statements to manipulate the back-end database.
Which versions of IBM Security Guardium are affected by CVE-2020-4990?
CVE-2020-4990 affects IBM Security Guardium versions 11.2 and earlier.
What database actions can an attacker perform through CVE-2020-4990?
An attacker exploiting CVE-2020-4990 can view, add, modify, or delete information in the database.