VYPR
Unrated severityNVD Advisory· Published Jul 7, 2021· Updated Sep 16, 2024

CVE-2021-20379

CVE-2021-20379

Description

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 195711.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Guardium Data Encryption (GDE) versions 3.0.0.3 and 4.0.0.4 use weak cryptographic algorithms, allowing attackers to decrypt sensitive data.

Vulnerability

IBM Guardium Data Encryption (GDE) versions 3.0.0.3 and 4.0.0.4 use weaker than expected cryptographic algorithms [1]. This vulnerability resides in the encryption implementation, potentially affecting all data protected by GDE in those versions. The weak algorithms could be exploited to decrypt highly sensitive information.

Exploitation

An attacker with network access to the encrypted data or the ability to intercept ciphertext could exploit the weak cryptographic algorithms. No authentication is required if the attacker can obtain the encrypted data. The attacker would need to perform cryptanalysis on the captured ciphertext to recover the plaintext.

Impact

Successful exploitation allows an attacker to decrypt highly sensitive information protected by GDE, leading to a loss of confidentiality. The impact is limited to data decryption; no code execution or privilege escalation is indicated.

Mitigation

IBM has fixed this vulnerability in GDE version 4.0.0.5 [1]. Users should upgrade to this version or later. No workarounds are mentioned in the available references. The vulnerability is not listed on the CISA KEV as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.