First published: Tue Jan 05 2021(Updated: )
IBM Guardium Data Encryption (GDE) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Guardium Data Encrpytion | =3.0.0.2 | |
<=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4160 is high with a CVSS score of 7.5.
IBM Guardium Data Encryption (GDE) is a security solution provided by IBM.
The affected version of IBM Guardium Data Encryption (GDE) is 3.0.0.2.
CVE-2019-4160 describes a vulnerability in IBM Guardium Data Encryption (GDE) where weaker than expected cryptographic algorithms are used, allowing an attacker to decrypt highly sensitive information.
To fix CVE-2019-4160, it is recommended to update IBM Guardium Data Encryption (GDE) to a version that does not use weaker cryptographic algorithms.