CVE-2018-1946

MEDIUM

IBM Security Identity Governance and Intelligence 5.2-5.2.4.1 - Inadequate Encryption Strength

Title source: llm
STIX 2.1

Description

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 153388.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10872142
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/153388

Scores

CVSS v3 5.9
EPSS 0.0073
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-326
Status published
Products (1)
ibm/security_identity_governance_and_intelligence 5.2 - 5.2.4.1
Published Feb 21, 2019
Tracked Since Feb 18, 2026