First published: Tue Jan 05 2021(Updated: )
IBM Guardium Data Encryption (GDE) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Guardium Data Encrpytion | =3.0.0.2 | |
IBM GDE | <=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2019-4687.
The severity of CVE-2019-4687 is medium with a CVSS score of 5.3.
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 and IBM GDE are affected by CVE-2019-4687.
CVE-2019-4687 may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Yes, you can find references for CVE-2019-4687 at the following links: [reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/171823) and [reference 2](https://www.ibm.com/support/pages/node/6403331).