First published: Mon Dec 18 2017(Updated: )
IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 132611.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =10.0 | |
IBM InfoSphere Guardium z/OS | =10.0.1 | |
IBM InfoSphere Guardium z/OS | =10.1.0 | |
IBM InfoSphere Guardium z/OS | =10.1.2 | |
IBM InfoSphere Guardium z/OS | =10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1598 has a medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2017-1598, upgrade to a patched version of IBM Security Guardium that employs stronger cryptographic algorithms.
CVE-2017-1598 affects IBM Security Guardium versions 10.0, 10.0.1, 10.1.0, 10.1.2, and 10.1.3.
CVE-2017-1598 puts highly sensitive information at risk due to the use of weak cryptographic algorithms.
Using vulnerable versions of IBM Security Guardium is not safe as they may expose sensitive data to potential attackers.