CVE-2021-20379: High severity ibm security guardium data encryption vulnerability
Published Jun 25, 2021
·Updated
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.
Other sources
IBM Guardium Data Encryption (GDE) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Affected Software
4 affected components
IBM Guardium Data Encryption=3.0.0.3
IBM Guardium Data Encryption=4.0.0.4
IBM GDE<=3.0.0.2
IBM GDE<=4.0.0.4
Remediation
Patch Available
Event History
Jun 25, 2021
CVE Published
via IBM·12:00 AM
Jul 7, 2021
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-20379.
2
What is the severity of CVE-2021-20379?
The severity of CVE-2021-20379 is high.
3
Which software versions are affected by CVE-2021-20379?
IBM Guardium Data Encryption (GDE) versions 3.0.0.2 to 4.0.0.4 are affected by CVE-2021-20379.
4
What is the risk associated with CVE-2021-20379?
CVE-2021-20379 could allow an attacker to decrypt highly sensitive information.
5
Are there any remediation steps available for CVE-2021-20379?
Refer to the IBM support page for detailed remediation steps for CVE-2021-20379.