QID 375423
QID 375423: IBM Security Guardium Java SDK Vulnerability (6405952)
Guardium is a comprehensive data protection platform that enables security teams to automatically analyze sensitive-data environments such as databases, data warehouses, big data platforms, cloud environments, file systems, mainframes.
CVE-2020-4688: IBM Security Guardium could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability.
CVE-2020-4921: IBM Security Guardium is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Version:
IBM Security Guardium 10.6
IBM Security Guardium 11.1
IBM Security Guardium 11.2
QID Detection Logic(Authenticated):
This qid will check the vulnerable version of installed IBM Security Guardium
Successful exploit could allow the attacker to view, add, modify or delete information in the back-end database and a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability.
- 6405952 -
www.ibm.com/support/pages/node/6405952
CVEs related to QID 375423
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6405952 |
|