First published: Mon Oct 28 2019(Updated: )
IBM Security Guardium Big Data Intelligence (SonarG) stores user credentials in plain in clear text which can be read by a local user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Big Data Intelligence | =4.0 | |
<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4307 has a medium severity level due to the risk of local user exploitation of stored credentials.
To fix CVE-2019-4307, update to IBM Security Guardium Big Data Intelligence version 4.1 or later.
CVE-2019-4307 affects IBM Security Guardium Big Data Intelligence version 4.0.
CVE-2019-4307 is a credential storage vulnerability that exposes user credentials in plain text.
Yes, local users can exploit CVE-2019-4307 by accessing stored user credentials in plain text.