Weak Permission Management in IBM Security Guardium Data Encryption
CVE-2019-4702

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
13 January 2021

What is CVE-2019-4702?

IBM Security Guardium Data Encryption version 3.0.0.2 has a vulnerability where permissions for a critical resource are improperly set. This misconfiguration may enable unauthorized users to read or modify sensitive data, potentially leading to significant security breaches. Organizations using this version should review their permission settings to mitigate associated risks.

Affected Version(s)

Security Guardium Data Encryption 3.0.0.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.