CVE-2021-39025: Medium severity ibm 1 vulnerability
Published Mar 8, 2022
·Updated
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down. IBM X-Force 213863.
Other sources
IBM Guardium Data Encryption (GDE) could disclose internal IP address information when the web backend is down.
— IBM
Affected Software
5 affected components
IBM 1.10.1 and lower<=1.10.1 and lower
IBM 2.6.3 and lower<=2.6.3 and lower
IBM 4.0.0.7 and lower<=4.0.0.7 and lower
IBM Guardium Data Encryption=4.0.0.0
IBM Guardium Data Encryption=5.0.0.0
Remediation
Patch Available
Event History
Mar 8, 2022
CVE Published
via IBM·12:00 AM
Mar 10, 2022
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-39025.
2
What is the severity of CVE-2021-39025?
The severity of CVE-2021-39025 is medium.
3
Which software versions are affected by CVE-2021-39025?
IBM Guardium Data Encryption (GDE) versions 4.0.0.0 and 5.0.0.0 are affected by CVE-2021-39025.
4
How does CVE-2021-39025 impact IBM Guardium Data Encryption?
CVE-2021-39025 allows for the disclosure of internal IP address information when the web backend is down in IBM Guardium Data Encryption.
5
Where can I find more information about CVE-2021-39025?
You can find more information about CVE-2021-39025 on the IBM X-Force website.