First published: Mon Nov 27 2023(Updated: )
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =11.3 | |
IBM InfoSphere Guardium z/OS | =11.4 | |
IBM InfoSphere Guardium z/OS | =11.5 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
IBM InfoSphere Guardium z/OS | <=11.4 | |
IBM InfoSphere Guardium z/OS | <=11.5 | |
IBM BM Security Guardium | <=12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-42004 is high.
IBM Security Guardium versions 11.3, 11.4, and 11.5 are affected by CVE-2023-42004.
CSV injection is a technique where an attacker injects malicious commands into a CSV file, which can lead to the execution of those commands.
A remote attacker can exploit CVE-2023-42004 by executing malicious commands through a CSV file.
Please refer to the official IBM Security Guardium documentation or contact IBM support for information on how to fix CVE-2023-42004.