Show filters
136 Total Results
Displaying 41-50 of 136
Sort by:
Attacker Value
Unknown
CVE-2019-4693
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.
0
Attacker Value
Unknown
CVE-2019-4713 — IBM Security Guardium Data Encryption code execution
Disclosure Date: August 26, 2020 (last updated November 28, 2024)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172084.
0
Attacker Value
Unknown
CVE-2019-4688
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.
0
Attacker Value
Unknown
CVE-2019-4686
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171822.
0
Attacker Value
Unknown
CVE-2019-4694
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.
0
Attacker Value
Unknown
CVE-2019-4692
Disclosure Date: August 26, 2020 (last updated November 28, 2024)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 171829.
0
Attacker Value
Unknown
CVE-2020-5385
Disclosure Date: August 18, 2020 (last updated February 22, 2025)
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.
0
Attacker Value
Unknown
CVE-2020-5358
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.
0
Attacker Value
Unknown
CVE-2016-6590
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-3745
Disclosure Date: October 03, 2019 (last updated November 27, 2024)
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.
0