Vulnerabilities > IBM

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2020-4604 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local privileged user.
local
low complexity
ibm CWE-312
2.1
2021-01-13 CVE-2020-4602 Insufficiently Protected Credentials vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1
2021-01-13 CVE-2020-4600 Information Exposure Through AN Error Message vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.0
2021-01-13 CVE-2020-4599 Information Exposure Through AN Error Message vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.0
2021-01-13 CVE-2020-4597 Missing Encryption of Sensitive Data vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies.
network
ibm CWE-311
4.3
2021-01-13 CVE-2020-4596 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2020-4595 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2020-4594 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2019-4702 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Security Guardium Data Encrpytion 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-732
5.5
2021-01-13 CVE-2019-4687 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium Data Encrpytion 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters.
network
low complexity
ibm CWE-312
5.0