VulnerabilityModified
CVE-2018-1425
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
MEDIUM 5.9EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139003.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- ibm/security guardium big data intelligence
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22013751Vendor Advisory
- http://www.securityfocus.com/bid/103229Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139033VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22013751Vendor Advisory
- http://www.securityfocus.com/bid/103229Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139033VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.