IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
Solution:
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7234827 | vendor advisory |