VYPR
Unrated severityNVD Advisory· Published Jul 12, 2021· Updated Sep 17, 2024

CVE-2021-20414

CVE-2021-20414

Description

IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Guardium Data Encryption (GDE) 3.0.0.2 allows brute-force attacks on sensitive information due to insufficient rate limiting.

Vulnerability

IBM Guardium Data Encryption (GDE) version 3.0.0.2 fails to enforce a limit on the number of authentication attempts, enabling an attacker to brute-force sensitive information such as passwords or encryption keys [1]. The vulnerability resides in the authentication mechanism and is reachable over the network without user interaction.

Exploitation

An attacker with network access and high-privilege credentials (CVSS:PR:H) can exploit this flaw by repeatedly sending authentication requests to the GDE service [1]. The attack complexity is high (AC:H), but no user interaction is required. The lack of rate limiting allows the attacker to perform a brute-force attack until successful.

Impact

Successful exploitation results in the disclosure of sensitive information (confidentiality impact: high) [1]. An attacker with existing high privileges can obtain additional protected data, such as encryption keys or other secrets, compromising the confidentiality of the system.

Mitigation

IBM has fixed this vulnerability in Guardium Tokenization Server version 2.6.0.205 [1]. Users should upgrade to this version or later. No workarounds are provided, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.