First published: Mon Jan 31 2022(Updated: )
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =5.0.0.2 | |
<=CM 2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39021.
The severity of CVE-2021-39021 is medium with a CVSS score of 5.3.
The affected software is IBM Guardium Data Encryption (GDE) 5.0.0.2.
The vulnerability causes IBM Guardium Data Encryption (GDE) 5.0.0.2 to behave differently or send different responses under different circumstances, allowing unauthorized actors to observe user enumeration.
Yes, you can find references for CVE-2021-39021 at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/213856) and [Link 2](https://www.ibm.com/support/pages/node/6552552).