Lucene search

K
ibmIBM98CC07A5EC806BB704F5168C0EB57B4E602875705FE86788B6A83BA271D91178
HistoryMay 04, 2022 - 12:14 p.m.

Security Bulletin: IBM Security Guardium Data Encryption has vulnerability ( CVE-2021-39020)

2022-05-0412:14:42
www.ibm.com
17

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

25.0%

Summary

IBM Guardium Data Encryption (GDE) stores sensitive information in URL parameters. Please apply the latest version for the fixes.

Vulnerability Details

CVEID:CVE-2021-39020
**DESCRIPTION:**IBM Guardium Data Encryption (GDE) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
CVSS Base score: 2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213855 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

Product Name Component Name Affected Version
IBM Guardium Data Encryption (GDE) Vormetric Data Security Manager (DSM) GDE Server 4.0.0.7 and lower

Remediation/Fixes

Please apply the fix from below links, to obtain the fixes.
Note: In order to get the fix, customer needs to login to Thales portal.

Component Name Fixed in version Patch/Upgrade link
Vormetric Data Security Manager GDE Server 4.0.0.7 ( DSM 6.4.7) https://supportportal.thalesgroup.com/csm?id=kb_article_view&sys_kb_id=4f1986971b0e4510b840c84b1d4bcbc4&sysparm_article=KB0025645

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmguardium_data_encryptionMatch4.0.0.
OR
ibmguardium_data_encryptionMatch5.0.0.

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

25.0%

Related for 98CC07A5EC806BB704F5168C0EB57B4E602875705FE86788B6A83BA271D91178