First published: Thu May 20 2021(Updated: )
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =11.2 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4990 is classified as a critical vulnerability due to its potential for unauthorized database access through SQL injection.
To mitigate CVE-2020-4990, users should apply the security patches provided by IBM for versions up to 11.2 of IBM Security Guardium.
CVE-2020-4990 can be exploited by remote attackers using specially crafted SQL statements to manipulate the back-end database.
CVE-2020-4990 affects IBM Security Guardium versions 11.2 and earlier.
An attacker exploiting CVE-2020-4990 can view, add, modify, or delete information in the database.