Ibm Security Guardium Key Lifecycle Manager vulnerabilities
29 known vulnerabilities affecting ibm/security_guardium_key_lifecycle_manager.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM16LOW2
Vulnerabilities
Page 1 of 2
CVE-2024-49819HIGHCVSS 7.5v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49819 [MEDIUM] CWE-319 CVE-2024-49819: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attack
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
cvelistv5nvd
CVE-2024-49817MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49817 [MEDIUM] CWE-260 CVE-2024-49817: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
cvelistv5nvd
CVE-2024-49816MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49816 [MEDIUM] CWE-532 CVE-2024-49816: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitiv
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
cvelistv5nvd
CVE-2024-49818MEDIUMCVSS 4.3v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49818 [MEDIUM] CWE-209 CVE-2024-49818: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote atta
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-49820LOWCVSS 3.7v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49820 [LOW] CWE-319 CVE-2024-49820: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attack
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
cvelistv5nvd
CVE-2023-25921HIGHCVSS 8.8≥ 3.0.0, < 4.1.1.7v3.0, 3.0.1, 4.0, 4.1, 4.1.12024-02-29
CVE-2023-25921 [HIGH] CWE-434 CVE-2023-25921:
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
cvelistv5nvd
CVE-2023-25926HIGHCVSS 8.2≥ 3.0.0, < 4.1.1.7v3.0, 3.0.1, 4.0, 4.1, 4.1.12024-02-29
CVE-2023-25926 [MEDIUM] CWE-611 CVE-2023-25926: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 247599.
cvelistv5nvd
CVE-2023-25925HIGHCVSS 8.8≥ 3.0.0, < 4.1.1.7v3.0, 3.0.1, 4.0, 4.1, 4.1.12024-02-28
CVE-2023-25925 [HIGH] CWE-78 CVE-2023-25925: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote aut
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.
cvelistv5nvd
CVE-2023-25922HIGHCVSS 8.8≥ 3.0.0, < 4.1.1.7v3.0, 3.0.1, 4.0, 4.1, 4.1.12024-02-28
CVE-2023-25922 [MEDIUM] CWE-434 CVE-2023-25922: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to u
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
cvelistv5nvd
CVE-2023-47702CRITICALCVSS 9.1≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47702 [MEDIUM] CWE-22 CVE-2023-47702: IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directorie
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.
cvelistv5nvd
CVE-2023-47704HIGHCVSS 7.5≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47704 [MEDIUM] CWE-798 CVE-2023-47704: IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
cvelistv5nvd
CVE-2023-47706HIGHCVSS 8.8≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47706 [MEDIUM] CWE-434 CVE-2023-47706: IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.
cvelistv5nvd
CVE-2023-47707MEDIUMCVSS 5.4≥ 4.2.0, ≤ 4.2.0.2v4.32023-12-20
CVE-2023-47707 [MEDIUM] CWE-79 CVE-2023-47707: IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerab
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
cvelistv5nvd
CVE-2023-47705MEDIUMCVSS 4.3≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47705 [MEDIUM] CWE-20 CVE-2023-47705: IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate user
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
cvelistv5nvd
CVE-2023-47703MEDIUMCVSS 5.3≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47703 [MEDIUM] CWE-209 CVE-2023-47703: IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive in
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.
cvelistv5nvd
CVE-2021-38980MEDIUMCVSS 5.3≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-23
CVE-2021-38980 [MEDIUM] CWE-209 CVE-2021-38980: IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.
nvd
CVE-2021-38979HIGHCVSS 7.5v4.1.0v4.1.0.1+1 more2021-11-15
CVE-2021-38979 [HIGH] CWE-916 CVE-2021-38979: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
nvd
CVE-2021-38983HIGHCVSS 7.5v4.1.0v4.1.0.1+1 more2021-11-15
CVE-2021-38983 [HIGH] CWE-326 CVE-2021-38983: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
nvd
CVE-2021-38984HIGHCVSS 7.5≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-15
CVE-2021-38984 [HIGH] CWE-326 CVE-2021-38984: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
nvd
CVE-2021-38982MEDIUMCVSS 5.4v4.1.0v4.1.0.1+1 more2021-11-15
CVE-2021-38982 [MEDIUM] CWE-79 CVE-2021-38982: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. Thi
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
nvd
1 / 2Next →