First published: Tue Aug 11 2020(Updated: )
IBM Guardium Data Encryption (GDE) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =3.0.0.2 | |
Ibm Guardium For Cloud Key Management | <1.7.0 | |
<=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4698
The severity of CVE-2019-4698 is high with a severity value of 7.5.
IBM Guardium Data Encryption (GDE) versions up to and including 3.0.0.2 are affected by CVE-2019-4698.
CVE-2019-4698 makes it easier for attackers to compromise user accounts as IBM Guardium Data Encryption (GDE) 3.0.0.2 does not require strong passwords by default.
To fix CVE-2019-4698, users should ensure that strong passwords are used for IBM Guardium Data Encryption (GDE) accounts.