PT-2020-11033 · Ibm · Ibm Security Guardium Data Encryption
Published
2020-08-26
·
Updated
2020-08-27
·
CVE-2019-4699
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Guardium Data Encryption (GDE) version 3.0.0.2
Description
The issue concerns an error message generated by the software that includes sensitive information about its environment, users, or associated data.
Recommendations
For version 3.0.0.2, consider implementing measures to restrict access to error messages and sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Guardium Data Encryption