VYPR
Unrated severityNVD Advisory· Published Jan 13, 2021· Updated Sep 17, 2024

CVE-2019-4160

CVE-2019-4160

Description

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Guardium Data Encryption (GDE) 3.0.0.2 uses weak cryptographic algorithms, allowing attackers to decrypt sensitive information.

Vulnerability

IBM Guardium Data Encryption (GDE) version 3.0.0.2 uses weaker than expected cryptographic algorithms, as described in the official CVE entry and referenced in the IBM security bulletin [1]. This weakness could allow an attacker to decrypt highly sensitive information protected by the product. The affected version is explicitly GDE 3.0.0.2.

Exploitation

An attacker would need network access to the system running the affected GDE version. The weak cryptographic algorithms can be exploited through passive interception of encrypted data or by gaining access to encrypted storage. No authentication is required for the cryptographic weakness itself, though the attacker must be able to obtain the encrypted data in transit or at rest.

Impact

Successful exploitation results in the attacker being able to decrypt highly sensitive information that was intended to be protected by GDE. This leads to a direct compromise of confidentiality (information disclosure) of the encrypted data. The severity of the impact is high, as the product is designed to protect sensitive data.

Mitigation

IBM has not explicitly disclosed a fixed version in the available references [1]. Users should consult the IBM support page for the latest updates and apply any available patches. Until a fix is applied, organizations should review and possibly replace the use of weak cryptographic algorithms within their GDE configuration, if feasible. No KEV listing was found for this CVE.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.