CVE-2021-39077Cleartext Transmission of Sensitive Info in IBM Security Guardium

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 94.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 3
Latest updateNov 4

Description

IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/security_guardium11.011.4+2
CVEListV5ibm/security_guardium10.5, 10.6, 11.0, 11.1, 11.2, 11.3, 11.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-46g7-vhp2-8mj6: "IBM Security Guardium 102022-11-04
CVEList
IBM Security Guardium information disclosure2022-11-03
CVE-2021-39077 — IBM Security Guardium vulnerability | cvebase