CVE-2021-38980

CWE-2093 documents3 sources
Severity
5.3MEDIUM
EPSS
0.2%
top 61.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateNov 24

Description

IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-crr7-h45x-f39h: IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 32021-11-24
CVEList
CVE-2021-38980: IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 32021-11-23
CVE-2021-38980 (MEDIUM CVSS 5.3) | IBM Tivoli Key Lifecycle Manager (I | cvebase.io