CVE-2019-4697
Published Aug 13, 2020
·Updated
IBM Guardium Data Encryption (GDE) stores user credentials in plain in clear text which can be read by an authenticated user.
Affected Software
3 affected components
IBM Guardium Data Encryption=3.0.0.2
IBM Guardium For Cloud Key Management<1.7.0
IBM GDE<=3.0.0.2
Remediation
Patch Available
Event History
Aug 13, 2020
CVE Published
via IBM·12:00 AM
Aug 26, 2020
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-4697.
2
What is the severity level of CVE-2019-4697?
The severity level of CVE-2019-4697 is medium (6.5).
3
What is the affected software?
The affected software includes IBM Guardium Data Encryption (GDE) 3.0.0.2 and IBM GDE up to version 3.0.0.2, as well as IBM Guardium for Cloud Key Management up to version 1.7.0.
4
How can an authenticated user read the plain text user credentials?
An authenticated user can read the plain text user credentials by accessing the storage location where they are stored.
5
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM Support page for more information.