CVE-2021-20474
- EPSS 0.04%
- Veröffentlicht 07.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:38
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVE-2021-20417
- EPSS 0.05%
- Veröffentlicht 07.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:33
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-F...
CVE-2021-20416
- EPSS 0.09%
- Veröffentlicht 07.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:33
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information f...
CVE-2021-20415
- EPSS 0.09%
- Veröffentlicht 07.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:33
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.
CVE-2021-20379
- EPSS 0.05%
- Veröffentlicht 07.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:29
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.
- EPSS 0.09%
- Veröffentlicht 28.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:32
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-F...
CVE-2019-4695
- EPSS 0.02%
- Veröffentlicht 26.08.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:00
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 171926.
- EPSS 6.77%
- Veröffentlicht 26.08.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:02
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary com...
CVE-2019-4701
- EPSS 0.08%
- Veröffentlicht 26.08.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:01
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 171936.
- EPSS 0.08%
- Veröffentlicht 26.08.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:01
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 171931.