First published: Thu Apr 28 2022(Updated: )
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 213855.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | <=4.0.0.7 | |
<=GDE Server 4.0.0.7 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39020 is a vulnerability in IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower where sensitive information is stored in URL parameters, potentially leading to information disclosure.
The severity of CVE-2021-39020 is medium with a CVSS score of 5.3.
CVE-2021-39020 can lead to information disclosure if unauthorized parties have access to the URLs containing sensitive information.
IBM Guardium Data Encryption 4.0.0.7 and lower are affected by CVE-2021-39020.
To mitigate CVE-2021-39020, it is recommended to upgrade to a version higher than 4.0.0.7.