First published: Fri Apr 15 2022(Updated: )
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium | =10.5 | |
Linux Linux kernel | ||
IBM Security Guardium | <=10.5 | |
IBM Security Guardium | <=10.6 | |
IBM Security Guardium | <=11.0 | |
IBM Security Guardium | <=11.1 | |
IBM Security Guardium | <=11.3 | |
IBM Security Guardium | <=11.2 | |
IBM Security Guardium | <=11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39078.
The severity rating of CVE-2021-39078 is medium (4.4).
IBM Security Guardium stores user credentials in plain clear text.
A local privileged user can read the user credentials stored by IBM Security Guardium.
To fix the vulnerability in IBM Security Guardium, update to a version that does not store user credentials in plain clear text and restrict access to privileged users.