Vulnerabilities > IBM > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2020-4599 Information Exposure Through an Error Message vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
5.0
2021-01-13 CVE-2020-4597 Missing Encryption of Sensitive Data vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or session cookies.
network
ibm CWE-311
4.3
2021-01-13 CVE-2020-4596 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2020-4595 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2020-4594 Inadequate Encryption Strength vulnerability in IBM Security Guardium Insights 2.0.2
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-13 CVE-2019-4702 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Security Guardium Data Encrpytion 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-732
5.5
2021-01-13 CVE-2019-4687 Cleartext Storage of Sensitive Information vulnerability in IBM Security Guardium Data Encrpytion 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters.
network
low complexity
ibm CWE-312
5.0
2021-01-13 CVE-2019-4160 Inadequate Encryption Strength vulnerability in IBM Security Guardium Data Encrpytion 3.0.0.2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2021-01-12 CVE-2020-4674 Insecure Storage of Sensitive Information vulnerability in IBM Workload Automation 9.5
IBM Workload Automation 9.5 stores the server path in URLs that could aid in further attacks against the system.
network
low complexity
ibm CWE-922
4.0
2021-01-12 CVE-2020-4673 Insecure Storage of Sensitive Information vulnerability in IBM Workload Automation 9.5
IBM Workload Automation 9.5 stores sensitive information in HTML comments that could aid in further attacks against the system.
network
low complexity
ibm CWE-922
4.0