cbcvebase.

Ibm Security Guardium Key Lifecycle Manager vulnerabilities

29 known vulnerabilities affecting ibm/security_guardium_key_lifecycle_manager.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM16LOW2

Vulnerabilities

Page 2 of 2
CVE-2021-38985P4MEDIUMCVSS 4.3≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38985 [MEDIUM] CWE-20 CVE-2021-38985: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
CVE-2021-38972P4MEDIUMCVSS 4.3≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38972 [MEDIUM] CWE-20 CVE-2021-38972: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
CVE-2023-47705P4MEDIUMCVSS 4.3≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47705 [MEDIUM] CWE-20 CVE-2023-47705: IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate user IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
nvd
CVE-2021-38977P4MEDIUMCVSS 4.3v4.1.0v4.1.0.1+1 more2021-11-15
CVE-2021-38977 [MEDIUM] CWE-311 CVE-2021-38977: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on autho IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain t
nvd
CVE-2024-49817P4MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49817 [MEDIUM] CWE-260 CVE-2024-49817: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
nvd
CVE-2024-49816P4MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49816 [MEDIUM] CWE-532 CVE-2024-49816: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitiv IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
nvd
CVE-2024-49818P4MEDIUMCVSS 4.3v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49818 [MEDIUM] CWE-209 CVE-2024-49818: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote atta IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2024-49820P4LOWCVSS 3.7v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49820 [LOW] CWE-319 CVE-2024-49820: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attack IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2021-38973P4LOWCVSS 2.7≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38973 [LOW] CWE-20 CVE-2021-38973: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
Ibm Security Guardium Key Lifecycle Manager vulnerabilities | cvebase