CVE-2018-1749
published 2018-10-08CVE-2018-1749: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
0.90%
56.1th percentile
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_key_lifecycle_manager | — | — |
| ibm | security_key_lifecycle_manager | — | — |
| ibm | security_key_lifecycle_manager | — | — |
| ibm | security_key_lifecycle_manager | 2.6.0 – 2.6.0.4 | — |
| ibm | security_key_lifecycle_manager | 2.7.0 – 2.7.0.3 | — |
| ibm | security_key_lifecycle_manager | 3.0 – 3.0.0.1 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3885 pacemaker: Information disclosure through use-after-free
bugzilla·2019-04-01·CVSS 7.8
CVE-2019-3885 [HIGH] CVE-2019-3885 pacemaker: Information disclosure through use-after-free
CVE-2019-3885 pacemaker: Information disclosure through use-after-free
A use-after-free defect was discovered in pacemaker that can possibly lead to unsolicited information disclosure in the log outputs.
Discussion:
Acknowledgments:
Name: Jan Pokorný (Red Hat)
---
Created attachment 1555736
Cumulative patches to address CVE-2018-16877, CVE-2018-16878 and CVE-2019-3885
---
Public via:
https://www.openwall.com/lists/oss-security/2019/04/17/1
---
Created pacemaker tracking bugs for this issue:
Affects: fedora-all [bug 1700737]
---
Upstream patch: https://github.com/ClusterLabs/pacemaker/pull/1749/commits/970736b1c7ad5c78cc5295a4231e546104d55893
---
Created pacemaker tracking bugs for this issue:
Affects: openstack-rdo [bug 1706307]
---
This issue has been addressed in the fo
Bugzilla
CVE-2018-16878 pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS
bugzilla·2018-12-10·CVSS 7.8
CVE-2018-16878 [HIGH] CVE-2018-16878 pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS
CVE-2018-16878 pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS
A flaw was found in pacemaker. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1649942
Discussion:
Acknowledgments:
Name: Jan Pokorný (Red Hat)
---
Created attachment 1555735
Cumulative patches to address CVE-2018-16877, CVE-2018-16878 and CVE-2019-3885
---
Public via:
https://www.openwall.com/lists/oss-security/2019/04/17/1
---
Created pacemaker tracking bugs for this issue:
Affects: fedora-all [bug 1700737]
---
Upstream patch: https://github.com/ClusterLabs/pacemaker/pull/1749/commits/970736b1c7ad5c78cc5295a4231e546104d55893
---
Created pacemaker tracking bugs
2018-10-08
Published