CVE-2019-4693: Medium severity ibm security guardium data encryption vulnerability
Published Aug 11, 2020
·Updated
IBM Guardium Data Encryption (GDE) stores user credentials in plain in clear text which can be read by a local privileged user.
Other sources
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.
Affected Software
3 affected components
IBM Guardium Data Encryption=3.0.0.2
IBM Guardium For Cloud Key Management<1.7.0
IBM GDE<=3.0.0.2
Remediation
Patch Available
Event History
Aug 11, 2020
CVE Published
via IBM·12:00 AM
Aug 26, 2020
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4693?
The severity of CVE-2019-4693 is medium.
2
Which software versions are affected by CVE-2019-4693?
IBM Guardium Data Encryption (GDE) version 3.0.0.2 is affected by CVE-2019-4693.
3
Is user credential storage in plain text the vulnerability in CVE-2019-4693?
Yes, storing user credentials in plain text is the vulnerability in CVE-2019-4693.
4
How can a local privileged user exploit CVE-2019-4693?
A local privileged user can exploit CVE-2019-4693 by reading the user credentials stored in plain text.
5
Where can I find more information about CVE-2019-4693?
You can find more information about CVE-2019-4693 on the IBM X-Force ID 171831 page and the IBM Support page.