#VU68847 Unprotected storage of credentials in IBM Security Guardium - CVE-2021-39077
Published: October 31, 2022
IBM Security Guardium
IBM Corporation
Description
The vulnerability allows a local privileged user to gain access to other users' credentials.
The vulnerability exists due to IBM Security Guardium stores user credentials in plain clear text which can be read by a local privileged user. A local privileged user can view contents of the configuration file and gain access to passwords for 3rd party integration.