First published: Thu Aug 13 2020(Updated: )
IBM Guardium Data Encryption (GDE) contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =3.0.0.2 | |
Ibm Guardium For Cloud Key Management | <1.7.0 | |
<=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4694 refers to a vulnerability in IBM Guardium Data Encryption (GDE) where it contains hard-coded credentials, such as a password or cryptographic key.
CVE-2019-4694 has a severity rating of 9.8, which is considered critical.
CVE-2019-4694 affects IBM Guardium Data Encryption (GDE) version 3.0.0.2 and IBM GDE up to version 3.0.0.2 and IBM GDE up to version 1.7.0 for Guardium for Cloud Key Management.
The CWE-ID for CVE-2019-4694 is 798.
To fix the CVE-2019-4694 vulnerability, update IBM Guardium Data Encryption (GDE) to a version that does not contain the hard-coded credentials.