VYPR
Unrated severityNVD Advisory· Published Oct 28, 2019· Updated Sep 16, 2024

CVE-2019-4309

CVE-2019-4309

Description

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hard-coded credentials in IBM Guardium Big Data Intelligence (SonarG) 4.0 allow local user to obtain highly sensitive information.

Vulnerability

IBM Security Guardium Big Data Intelligence (SonarG) version 4.0 uses hard-coded credentials, enabling a local user to access highly sensitive information. This vulnerability is identified as CVE-2019-4309 and has a CVSS v3 base score of 5.9 (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). The issue exists in the software configuration and does not require any special privileges to trigger, but it demands local access to the system [1].

Exploitation

An attacker with local access to the system can exploit the hard-coded credentials to retrieve highly sensitive data. No authentication or user interaction is required beyond gaining local access. The attack complexity is high, as it may require specific knowledge of the credential storage location, but the attacker does not need an account on the target system [1].

Impact

Successful exploitation leads to the disclosure of highly sensitive information. The confidentiality impact is high, while integrity and availability are not affected. The compromised scope changes, meaning the attacker can access resources beyond the vulnerable component [1].

Mitigation

IBM has not released a patch or workaround for this vulnerability as of the publication date. The advisory states no workarounds or mitigations are available [1]. Users should monitor IBM's support page for future updates.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.