Lucene search

K
ibmIBMA32B6E2D2EC956CFD00BF7F271EDB22D454CF442147B646C9F4F746FCBD3BB16
HistorySep 25, 2022 - 10:31 p.m.

Security Bulletin: XML External Entity (XXE) security vulnerability in InfoSphere Guardium (CVE-2012-3340)

2022-09-2522:31:03
www.ibm.com
17
xxe
infosphere guardium
cve-2012-3340
vulnerability
remote authenticated
sensitive information
patch
password disclosure
ibm
security bulletin
linux

EPSS

0.002

Percentile

59.5%

Abstract

XML External Entity (XXE) security vulnerability in InfoSphere Guardium allows remote authenticated users to obtain sensitive information via unspecified vectors.

Content

VULNERABILITY DETAILS:
CVE ID: CVE-2012-3340

DESCRIPTION:
User can get to an error report containing content of a file on the server with database password.

CVSS:
CVSS Base Score: 4.0
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/78291&gt; for the current score
CVSS Environmental Score*: Undefined

AFFECTED PLATFORMS:
IBM InfoSphere Guardium 8.2 and earlier

REMEDIATION:
Apply the patch for password disclosure. - The patch is included within the latest GPU for each version.

As of August 24, 2012, the latest Guardium patches and GPU fixpacks for all versions are available through FixCentral.

REFERENCES:
ยท On-line Calculator V2
ยท X-Force Vulnerability Database
ยท CVE-2012-3312

RELATED INFORMATION:
ยท IBM Secure Engineering Web Portal
ยท IBM Product Security Incident Response Blog** **

[{โ€œProductโ€:{โ€œcodeโ€:โ€œSSMPHHโ€,โ€œlabelโ€:โ€œIBM Security Guardiumโ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU059โ€,โ€œlabelโ€:โ€œIBM Software w/o TPSโ€},โ€œComponentโ€:โ€œโ€“โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF016โ€,โ€œlabelโ€:โ€œLinuxโ€}],โ€œVersionโ€:โ€œ8.2;8.0.1;8.0โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB24โ€,โ€œlabelโ€:โ€œSecurity Softwareโ€}}]

EPSS

0.002

Percentile

59.5%

Related for A32B6E2D2EC956CFD00BF7F271EDB22D454CF442147B646C9F4F746FCBD3BB16