First published: Tue Mar 08 2022(Updated: )
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down. IBM X-Force 213863.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Data Encryption | =4.0.0.0 | |
IBM Guardium Data Encryption | =5.0.0.0 | |
IBM 1.10.1 and lower | <=1.10.1 and lower | |
IBM 2.6.3 and lower | <=2.6.3 and lower | |
IBM 4.0.0.7 and lower | <=4.0.0.7 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-39025.
The severity of CVE-2021-39025 is medium.
IBM Guardium Data Encryption (GDE) versions 4.0.0.0 and 5.0.0.0 are affected by CVE-2021-39025.
CVE-2021-39025 allows for the disclosure of internal IP address information when the web backend is down in IBM Guardium Data Encryption.
You can find more information about CVE-2021-39025 on the IBM X-Force website.