CVE-2021-20474: High severity ibm security guardium data encryption vulnerability
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Other sources
IBM Security Guardium does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20474?
The severity of CVE-2021-20474 is high with a severity value of 7.5.
What is the affected software for CVE-2021-20474?
The affected software for CVE-2021-20474 is IBM Guardium Data Encryption (GDE) versions 3.0.0.2 and 4.0.0.4.
Does IBM Guardium Data Encryption perform authentication for functionality that requires a provable user identity?
No, IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-20474?
The Common Weakness Enumeration (CWE) ID for CVE-2021-20474 is 306.