VendorsIBMguardium_data_encryption3.0.0.2
Vulnerabilities

IBM Guardium Data Encryption 3.0.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2019-4694
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.
Published 2020-08-26 · Modified
9.8EPSS 0.012
CVE-2019-4713
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172084.
Published 2020-08-26 · Modified
9.0EPSS 0.026
CVE-2021-20378
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
Published 2021-07-07 · Modified
8.8EPSS 0.004
CVE-2019-4698
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
Published 2020-08-26 · Modified
7.5EPSS 0.008
CVE-2021-20474
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Published 2021-07-07 · Modified
7.5EPSS 0.005
CVE-2019-4697
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 171938.
Published 2020-08-26 · Modified
6.5EPSS 0.005
CVE-2019-4693
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.
Published 2020-08-26 · Modified
6.0EPSS 0.002
CVE-2019-4692
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 171829.
Published 2020-08-26 · Modified
5.3EPSS 0.007
CVE-2019-4701
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 171936.
Published 2020-08-26 · Modified
5.3EPSS 0.007
CVE-2021-20414
IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.
Published 2021-07-12 · Modified
4.9EPSS 0.005
CVE-2019-4699
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 171931.
Published 2020-08-26 · Modified
4.0EPSS 0.005
CVE-2019-4695
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.
Published 2020-08-26 · Modified
4.0EPSS 0.002