First published: Thu Aug 13 2020(Updated: )
IBM Guardium Data Encryption (GDE) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | <4.0.0.3 | |
Ibm Guardium For Cloud Key Management | <1.7.0 | |
<=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2019-4688.
CVE-2019-4688 has a severity level of 4.3 (medium).
IBM Guardium Data Encryption (GDE) versions up to and including 3.0.0.2 are affected by CVE-2019-4688.
Attackers can exploit CVE-2019-4688 by sending a malicious http:// link to a user or by planting such a link on a website that the user visits.
You can find more information about CVE-2019-4688 at the following references: [link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/171825) and [link 2](https://www.ibm.com/support/pages/node/6320835).