cbcvebase.
CVE-2016-6102
published 2017-03-27

CVE-2016-6102: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties…

low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.

Affected

14 ranges
VendorProductVersion rangeFixed in
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibmsecurity_key_lifecycle_manager
ibm_corporationkey_lifecycle_manager
ibm_corporationkey_lifecycle_manager