CVE-2019-4686 describes a vulnerability in IBM Security Guardium Data Encryption (GDE) and Guardium for Cloud Key Management, where authorization tokens and session cookies lack the secure attribute. This oversight allows attackers to potentially intercept cookie values via insecure HTTP links, leading to unauthorized access to user sessions. Rated 5.3 MEDIUM on the CVSS scale, the vulnerability has a low impact on confidentiality and requires no user interaction or privileges to exploit. Despite its potential, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0.3CPE matchmatch criteria | cpe:2.3:a:ibm:guardium_data_encryption:*:*:*:*:*:*:*:* | ||
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:ibm:guardium_for_cloud_key_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.