CVE-2019-4687 describes an information disclosure vulnerability in IBM Security Guardium Data Encryption (GDE) version 3.0.0.2. Sensitive information is stored in URL parameters, which could be exposed through server logs, referrer headers, or browser history if accessed by unauthorized parties. This vulnerability has a CVSS v3.1 score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, with the primary impact being a potential loss of confidentiality. The EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.2CPE matchmatch criteria | cpe:2.3:a:ibm:security_guardium_data_encryption:3.0.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.