CVE-2021-39078Cleartext Storage of Sensitive Info in IBM Security Guardium

Severity
4.4MEDIUMNVD
EPSS
0.0%
top 93.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateApr 20

Description

IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-4685-5233-g3fq: IBM Security Guardium 102022-04-20
CVEList
CVE-2021-39078: IBM Security Guardium 102022-04-19
CVE-2021-39078 — Cleartext Storage of Sensitive Info | cvebase