First published: Wed May 04 2022(Updated: )
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 213860.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =1.10.1 | |
IBM Guardium Data Encryption | =2.6 | |
IBM Guardium Data Encryption | =2.6.4.21 | |
IBM Guardium Data Encryption | =4.0.0 | |
IBM Guardium Data Encryption | =5.0.0 | |
<=1.10.1 | ||
<=2.6.4.21 | ||
<=2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39023.
The severity of CVE-2021-39023 is high with a severity value of 7.5.
IBM Guardium Data Encryption 4.0.0 and 5.0.0 are affected by CVE-2021-39023.
A remote attacker can exploit CVE-2021-39023 by obtaining sensitive information when a detailed technical error message is returned in the browser.
Yes, you can find references for CVE-2021-39023 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/213860) and [Reference 2](https://www.ibm.com/support/pages/node/6582473).