CVE-2021-20378: High severity IBM Guardium Data Encryption vulnerability
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
Other sources
IBM Guardium Data Encryption (GDE) does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20378.
What is the severity of CVE-2021-20378?
The severity of CVE-2021-20378 is high.
Which products and versions are affected by CVE-2021-20378?
IBM Guardium Data Encryption (GDE) versions 3.0.0.2 and 4.0.0.4 are affected.
What is the impact of CVE-2021-20378?
The vulnerability could allow an authenticated user to impersonate another user on the system.
Are there any references available for CVE-2021-20378?
Yes, you can find references at the following URLs: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/195709), [Link 2](https://www.ibm.com/support/pages/node/6469407).