CVE-2019-4697: Medium severity ibm security guardium data encryption vulnerability
IBM Guardium Data Encryption (GDE) stores user credentials in plain in clear text which can be read by an authenticated user.
Other sources
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 171938.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-4697.
What is the severity level of CVE-2019-4697?
The severity level of CVE-2019-4697 is medium (6.5).
What is the affected software?
The affected software includes IBM Guardium Data Encryption (GDE) 3.0.0.2 and IBM GDE up to version 3.0.0.2, as well as IBM Guardium for Cloud Key Management up to version 1.7.0.
How can an authenticated user read the plain text user credentials?
An authenticated user can read the plain text user credentials by accessing the storage location where they are stored.
Is there a fix available for this vulnerability?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM Support page for more information.