First published: Thu Aug 13 2020(Updated: )
IBM Guardium Data Encryption (GDE) generates an error message that includes sensitive information about its environment, users, or associated data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =3.0.0.2 | |
Ibm Guardium For Cloud Key Management | <1.7.0 | |
<=3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4699 is medium.
IBM Guardium Data Encryption (GDE) 3.0.0.2 and IBM GDE up to version 3.0.0.2 are affected by CVE-2019-4699.
CVE-2019-4699 is a vulnerability in IBM Security Guardium Data Encryption (GDE) 3.0.0.2 that generates an error message including sensitive information.
The CWE ID of CVE-2019-4699 is 209.
IBM has not provided a specific fix for CVE-2019-4699, but recommends following their guidance and best practices for secure configuration and error handling.