First published: Fri May 21 2021(Updated: )
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 195766.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =11.2 | |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20385 is a vulnerability in IBM Security Guardium 11.2 that could allow a remote authenticated attacker to execute arbitrary commands on the system.
An attacker can exploit CVE-2021-20385 by sending a specially-crafted request to the system.
CVE-2021-20385 has a severity score of 8.4 out of 10, indicating a critical vulnerability.
IBM Security Guardium versions 10.5 up to and including 11.2 are affected by CVE-2021-20385.
To fix CVE-2021-20385, update your IBM Security Guardium to a version that is not affected by the vulnerability.