CVE-2021-39022
Published: Mar 10, 2022
Modified: Sep 16, 2024
CVSS v3.0
6.2
Description
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software. IBM X-Force ID: 213858.
| Vendor | Product | Versions |
|---|---|---|
IBM | Security Guardium Data Encryption | affected 4.0.0.0affected 5.0.0.0 |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/A:N/I:L/AC:H/UI:R/S:C/C:H/PR:H/AV:N/E:U/RL:O/RC:C
Availability
Integrity
Attack Complexity
User Interaction
Scope
Confidentiality
Privileges Required
Attack Vector
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now