First published: Fri Jun 25 2021(Updated: )
IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM GDE | <=3.0.0.2 | |
IBM Guardium Data Encryption | =3.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability allows a user to brute force sensitive information due to the lack of proper limitations on the number of interactions in IBM Guardium Data Encryption (GDE) version 3.0.0.2.
The severity rating of CVE-2021-20414 is medium with a value of 4.9.
IBM Guardium Data Encryption (GDE) version 3.0.0.2 is the affected product of vendor IBM.
An attacker could exploit CVE-2021-20414 by performing a brute force attack to obtain sensitive information.
Please refer to the IBM support page (https://www.ibm.com/support/pages/node/6470849) for information on available fixes or patches for CVE-2021-20414.