CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
59.8%
IBM Security Guardium uses Apache Kafka in deployed agents to handle event streaming. IBM Security Guardium has fixed this vulnerability by upgrading to kafka-3.0.0-0.
CVEID:CVE-2021-38153
**DESCRIPTION:**Apache Kafka could allow a remote attacker to obtain sensitive information, caused by a timing attack flaw due to the use of “Arrays.equals” to validate a password or key. By utilizing brute-force attack techniques, an attacker could exploit this vulnerability to obtain credentials information, and use this information to launch further attacks against the affected system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/209762 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Security Guardium | 11.0 |
IBM Security Guardium | 11.1 |
IBM Security Guardium | 11.2 |
IBM Security Guardium | 11.3 |
IBM Security Guardium | 11.4 |
IBM encourages customers to update their systems promptly.
IBM Security Guardium| 11.3| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=11.0&platform=Linux&function=fixId&fixids=SqlGuard_11.0p360_Bundle_Mar-24-2022&includeSupersedes=0&source=fc
IBM Security Guardium| 11.4| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=11.0&platform=Linux&function=fixId&fixids=SqlGuard_11.0p440_Bundle_Jun-03-2022&includeSupersedes=0&source=fc
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | security_guardium | 11.0 | cpe:2.3:a:ibm:security_guardium:11.0:*:*:*:*:*:*:* |
ibm | security_guardium | 11.1 | cpe:2.3:a:ibm:security_guardium:11.1:*:*:*:*:*:*:* |
ibm | security_guardium | 11.2 | cpe:2.3:a:ibm:security_guardium:11.2:*:*:*:*:*:*:* |
ibm | security_guardium | 11.3 | cpe:2.3:a:ibm:security_guardium:11.3:*:*:*:*:*:*:* |
ibm | security_guardium | 11.4 | cpe:2.3:a:ibm:security_guardium:11.4:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
59.8%