CVE-2023-42004: IBM Security Guardium CSV injection
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents. IBM X-Force ID: 265262.
Other sources
IBM Security Guardium is potentially vulnerable to CSV injection. A remote attacker could execute malicious commands due to improper validation of csv file contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42004?
The severity of CVE-2023-42004 is high.
Which versions of IBM Security Guardium are affected by CVE-2023-42004?
IBM Security Guardium versions 11.3, 11.4, and 11.5 are affected by CVE-2023-42004.
What is CSV injection?
CSV injection is a technique where an attacker injects malicious commands into a CSV file, which can lead to the execution of those commands.
How can a remote attacker exploit CVE-2023-42004?
A remote attacker can exploit CVE-2023-42004 by executing malicious commands through a CSV file.
Is there a fix for CVE-2023-42004?
Please refer to the official IBM Security Guardium documentation or contact IBM support for information on how to fix CVE-2023-42004.