Session Management Flaw in IBM Guardium Data Encryption Products
CVE-2021-20378

6.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
7 July 2021

Summary

A session management vulnerability exists in IBM Guardium Data Encryption versions 3.0.0.2 and 4.0.0.4 that fails to invalidate sessions after a user logs out. This imperfection can potentially enable an authenticated user to impersonate another user within the system, jeopardizing the integrity of user data and actions. Organizations utilizing these versions may be at risk of unauthorized access and data manipulation, highlighting the importance of timely security updates and proper user session handling.

Affected Version(s)

Guardium Data Encryption 3.0.0.2

Guardium Data Encryption 4.0.0.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.