Lucene search

K
cvelistIbmCVELIST:CVE-2019-4702
HistoryJan 13, 2021 - 5:40 p.m.

CVE-2019-4702

2021-01-1317:40:20
ibm
www.cve.org
2
ibm
security
guardium
data encryption
gde
3.0.0.2
vulnerability
permissions
resource

CVSS3

4.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

21.4%

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

CNA Affected

[
  {
    "product": "Security Guardium Data Encryption",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.0.2"
      }
    ]
  }
]

CVSS3

4.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

21.4%

Related for CVELIST:CVE-2019-4702