CVE-2021-20416: Medium severity ibm security guardium data encryption vulnerability
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 196218.
Other sources
IBM Guardium Data Encryption (GDE) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20416.
What is the severity rating of CVE-2021-20416?
CVE-2021-20416 has a severity rating of medium with a value of 5.3.
What is the affected software for CVE-2021-20416?
The affected software for CVE-2021-20416 includes IBM Guardium Data Encryption (GDE) versions 3.0.0.3 and 4.0.0.4.
How can a remote attacker exploit CVE-2021-20416?
A remote attacker can exploit CVE-2021-20416 by failing to set the HTTPOnly flag and obtaining sensitive information from the cookie.
Is there any additional information available for CVE-2021-20416?
Yes, you can find additional information for CVE-2021-20416 at the following references: [IBM X-Force ID: 196218](https://exchange.xforce.ibmcloud.com/vulnerabilities/196218) and [IBM Support Page](https://www.ibm.com/support/pages/node/6469407).