Ibm Security Guardium Key Lifecycle Manager vulnerabilities
29 known vulnerabilities affecting ibm/security_guardium_key_lifecycle_manager.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM16LOW2
Vulnerabilities
Page 2 of 2
CVE-2021-38985P4MEDIUMCVSS 4.3≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38985 [MEDIUM] CWE-20 CVE-2021-38985: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
CVE-2021-38972P4MEDIUMCVSS 4.3≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38972 [MEDIUM] CWE-20 CVE-2021-38972: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
CVE-2023-47705P4MEDIUMCVSS 4.3≥ 4.2.0, < 4.2.0.2v4.32023-12-20
CVE-2023-47705 [MEDIUM] CWE-20 CVE-2023-47705: IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate user
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
nvd
CVE-2021-38977P4MEDIUMCVSS 4.3v4.1.0v4.1.0.1+1 more2021-11-15
CVE-2021-38977 [MEDIUM] CWE-311 CVE-2021-38977: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on autho
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain t
nvd
CVE-2024-49817P4MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49817 [MEDIUM] CWE-260 CVE-2024-49817: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
nvd
CVE-2024-49816P4MEDIUMCVSS 4.4v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49816 [MEDIUM] CWE-532 CVE-2024-49816: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitiv
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
nvd
CVE-2024-49818P4MEDIUMCVSS 4.3v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49818 [MEDIUM] CWE-209 CVE-2024-49818: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote atta
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2024-49820P4LOWCVSS 3.7v4.1.0v4.1.1+3 more2024-12-17
CVE-2024-49820 [LOW] CWE-319 CVE-2024-49820: IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attack
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2021-38973P4LOWCVSS 2.7≥ 4.1.0, ≤ 4.1.0.1v4.1.12021-11-12
CVE-2021-38973 [LOW] CWE-20 CVE-2021-38973: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
← Previous2 / 2