XML External Entity Injection Vulnerability in IBM InfoSphere Guardium
CVE-2012-3340

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 September 2020

Summary

IBM InfoSphere Guardium versions 8.0, 8.01, and 8.2 are exposed to an XML external entity injection vulnerability due to insufficient validation of user inputs. This security flaw enables remote authenticated attackers to exploit the vulnerability, potentially leading to the unauthorized retrieval of sensitive information from the system, thereby compromising data integrity and confidentiality. For detailed insights, refer to the IBM support documentation and the X-Force vulnerability database.

Affected Version(s)

InfoSphere Guardium 8.0

InfoSphere Guardium 8.01

InfoSphere Guardium 8.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.