CVE-2017-1727Log File Information Exposure in IBM Security KEY Lifecycle Manager

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 60.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 4
Latest updateMay 14

Description

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/security_key_lifecycle_manager2.5, 2.6, 2.7+2

🔴Vulnerability Details

2
GHSA
GHSA-cp33-2fr5-4qrq: IBM Tivoli Key Lifecycle Manager 22022-05-14
CVEList
CVE-2017-1727: IBM Tivoli Key Lifecycle Manager 22018-01-04
CVE-2017-1727 — Log File Information Exposure in IBM | cvebase