First published: Fri May 21 2021(Updated: )
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
IBM InfoSphere Guardium z/OS | =11.2 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20557 is considered a critical vulnerability due to its potential for remote command execution on affected systems.
To fix CVE-2021-20557, upgrade IBM Security Guardium to version 11.3 or later.
Affected users include those operating IBM Security Guardium versions 10.5 through 11.2.
Yes, CVE-2021-20557 can potentially lead to data breaches as it allows attackers to execute arbitrary commands.
CVE-2021-20557 can be exploited via remote authenticated attacks that send specially crafted requests.