CVE-2018-1753Sensitive Information Exposure in IBM Security KEY Lifecycle Manager

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 69.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8
Latest updateMay 13

Description

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/security_key_lifecycle_manager2.6.02.6.0.4+2
CVEListV5ibm/security_key_lifecycle_manager2.6, 2.7, 3.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4m6h-hp8h-qr9q: IBM Tivoli Key Lifecycle Manager 22022-05-13
CVEList
CVE-2018-1753: IBM Tivoli Key Lifecycle Manager 22018-10-08
CVE-2018-1753 — Sensitive Information Exposure in IBM | cvebase