CVE-2021-39022: High severity ibm 1 vulnerability
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software. IBM X-Force ID: 213858.
Other sources
IBM Guardium Data Encryption (GDE) saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39022?
The severity of CVE-2021-39022 is high (8.8).
Which versions of IBM Guardium Data Encryption are affected by CVE-2021-39022?
IBM Guardium Data Encryption versions 4.0.0.0 and 5.0.0.0 are affected by CVE-2021-39022.
How does CVE-2021-39022 impact IBM Guardium Data Encryption?
CVE-2021-39022 allows user-provided information to be saved into a CSV file in a way that could be interpreted as a command when opened by spreadsheet software.
Are there any workarounds for CVE-2021-39022?
No known workarounds are available for CVE-2021-39022.
Where can I find more information about CVE-2021-39022?
More information about CVE-2021-39022 can be found on the IBM X-Force Exchange website and the IBM Support pages.