Lucene search

K
ibmIBMFC14A6420E000D37D8D681D09B7BD2CA6D6CC067DD5D1169B2ED1B8BFEF4B16A
HistorySep 25, 2022 - 10:31 p.m.

Security Bulletin: InfoSphere Guardium Remote File Disclosure Vulnerability (CVE-2012-3337)

2022-09-2522:31:03
www.ibm.com
7
infosphere guardium
remote file disclosure
sql injection
patch
download
ibm
security

EPSS

0.002

Percentile

59.5%

Abstract

Relative path traversal vulnerability in InfoSphere Guardium allows remote unauthenticated attackers to download arbitrary files via unspecified vectors.

Content

VULNERABILITY DETAILS:

CVE ID: CVE-2012-3337

DESCRIPTION:
Multiple SQL injection vulnerabilities in several files allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Note that at least one of these SQL injections can be performed by low-privileged users. Hacked GIM Server allows download of any file in the system

CVSS:
CVSS Base Score: 5.0
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/78284&gt; for the current score
CVSS Environmental Score*: Undefined

AFFECTED PLATFORMS:
IBM InfoSphere Guardium 8.2 and earlier

REMEDIATION:
Apply the patch for password disclosure which is within the latest GPU for each version.

As of August 24, 2012, the latest Guardium patches and GPU fixpacks for all versions are available through FixCentral.


REFERENCES:
ยท On-line Calculator V2
ยท X-Force Vulnerability Database
ยท CVE-2012-3312

RELATED INFORMATION:
ยท IBM Secure Engineering Web Portal
ยท IBM Product Security Incident Response Blog** **

[{โ€œProductโ€:{โ€œcodeโ€:โ€œSSMPHHโ€,โ€œlabelโ€:โ€œIBM Security Guardiumโ€},โ€œBusiness Unitโ€:{โ€œcodeโ€:โ€œBU059โ€,โ€œlabelโ€:โ€œIBM Software w/o TPSโ€},โ€œComponentโ€:โ€œโ€“โ€,โ€œPlatformโ€:[{โ€œcodeโ€:โ€œPF016โ€,โ€œlabelโ€:โ€œLinuxโ€}],โ€œVersionโ€:โ€œ8.2;8.0.1;8.0โ€,โ€œEditionโ€:โ€œโ€,โ€œLine of Businessโ€:{โ€œcodeโ€:โ€œLOB24โ€,โ€œlabelโ€:โ€œSecurity Softwareโ€}}]

EPSS

0.002

Percentile

59.5%

Related for FC14A6420E000D37D8D681D09B7BD2CA6D6CC067DD5D1169B2ED1B8BFEF4B16A