CVE-2019-4694: Critical severity ibm security guardium data encryption vulnerability
IBM Guardium Data Encryption (GDE) contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Other sources
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4694?
CVE-2019-4694 refers to a vulnerability in IBM Guardium Data Encryption (GDE) where it contains hard-coded credentials, such as a password or cryptographic key.
What is the severity of CVE-2019-4694?
CVE-2019-4694 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2019-4694?
CVE-2019-4694 affects IBM Guardium Data Encryption (GDE) version 3.0.0.2 and IBM GDE up to version 3.0.0.2 and IBM GDE up to version 1.7.0 for Guardium for Cloud Key Management.
What is the CWE-ID for CVE-2019-4694?
The CWE-ID for CVE-2019-4694 is 798.
How can I fix the CVE-2019-4694 vulnerability?
To fix the CVE-2019-4694 vulnerability, update IBM Guardium Data Encryption (GDE) to a version that does not contain the hard-coded credentials.