First published: Tue Mar 08 2022(Updated: )
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software. IBM X-Force ID: 213858.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =4.0.0.0 | |
IBM Guardium Data Encryption | =5.0.0.0 | |
<=1.10.1 and lower | ||
<=2.6.3 and lower | ||
<=4.0.0.8 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-39022 is high (8.8).
IBM Guardium Data Encryption versions 4.0.0.0 and 5.0.0.0 are affected by CVE-2021-39022.
CVE-2021-39022 allows user-provided information to be saved into a CSV file in a way that could be interpreted as a command when opened by spreadsheet software.
No known workarounds are available for CVE-2021-39022.
More information about CVE-2021-39022 can be found on the IBM X-Force Exchange website and the IBM Support pages.