CVE-2023-35893: IBM Security Guardium command execution
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 258824.
Other sources
IBM Security Guardium could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35893.
What is the severity of CVE-2023-35893?
The severity of CVE-2023-35893 is critical with a CVSS score of 9.9.
Which versions of IBM Security Guardium are affected by CVE-2023-35893?
IBM Security Guardium versions 10.6, 11.3, 11.4, and 11.5 are affected by CVE-2023-35893.
How can a remote authenticated attacker exploit CVE-2023-35893?
A remote authenticated attacker can exploit CVE-2023-35893 by sending a specially crafted request to execute arbitrary commands on the system.
Is there a fix available for CVE-2023-35893?
Yes, IBM has released a fix for CVE-2023-35893. Please refer to the IBM Security Guardium support page for more information.