cbcvebase.

Ibm Security Key Lifecycle Manager vulnerabilities

70 known vulnerabilities affecting ibm/security_key_lifecycle_manager.

Total CVEs
70
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM41LOW4

Vulnerabilities

Page 1 of 4
CVE-2017-1670P3CRITICALCVSS 9.8v2.5.0v2.5.0.1+17 more2018-01-09
CVE-2017-1670 [CRITICAL] CWE-89 CVE-2017-1670: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637.
nvd
CVE-2023-25684P3CRITICALCVSS 9.8v3.0v3.0.1+4 more2023-03-21
CVE-2023-25684 [CRITICAL] CWE-89 CVE-2023-25684: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL inj IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597.
nvd
CVE-2020-4567P3CRITICALCVSS 9.8v3.0.1v4.02020-07-29
CVE-2020-4567 [CRITICAL] CWE-307 CVE-2020-4567: IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.
nvd
CVE-2016-6095P3CRITICALCVSS 9.8v2.5.0v2.5.0.0+10 more2017-02-02
CVE-2016-6095 [CRITICAL] CWE-284 CVE-2016-6095: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could a IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
nvd
CVE-2023-25924P3HIGHCVSS 8.8v3.0v3.0.1+4 more2023-03-22
CVE-2023-25924 [HIGH] CWE-863 CVE-2023-25924: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authentic IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
nvd
CVE-2017-1666P3HIGHCVSS 8.1v2.5.0v2.5.0.1+17 more2018-01-09
CVE-2017-1666 [HIGH] CWE-611 CVE-2017-1666: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 133540.
nvd
CVE-2016-6105P3HIGHCVSS 8.2v2.5.0v2.5.0.0+10 more2017-02-01
CVE-2016-6105 [HIGH] CWE-284 CVE-2016-6105: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical r IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
nvd
CVE-2017-1671P3HIGHCVSS 7.5v2.5.0v2.5.0.1+17 more2018-01-09
CVE-2017-1671 [HIGH] CWE-22 CVE-2017-1671: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directo IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 133638.
nvd
CVE-2016-6104P3HIGHCVSS 7.2v2.5.0v2.5.0.0+10 more2017-02-07
CVE-2016-6104 [HIGH] CWE-434 CVE-2016-6104: IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary file IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute arbitrary code on the vulnerable system.
nvd
CVE-2016-6093P3CRITICALCVSS 9.8v2.5.0.0v2.5.0.1+12 more2017-06-08
CVE-2016-6093 [CRITICAL] CWE-255 CVE-2016-6093: IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
nvd
CVE-2018-1745P3HIGHCVSS 7.5≥ 2.7.0, ≤ 2.7.0.3≥ 3.0, ≤ 3.0.0.1+2 more2018-10-11
CVE-2018-1745 [HIGH] CWE-306 CVE-2018-1745: IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SK IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.
nvd
CVE-2018-1742P3CRITICALCVSS 9.3≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1742 [CRITICAL] CWE-798 CVE-2018-1742: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a passwo IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 148421.
nvd
CVE-2020-4574P3HIGHCVSS 7.5v3.0.1v4.02020-07-29
CVE-2020-4574 [HIGH] CWE-521 CVE-2020-4574: IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
nvd
CVE-2018-1747P3HIGHCVSS 7.1≥ 2.5.0, ≤ 2.5.0.9≥ 2.6.0, ≤ 2.6.0.4+6 more2018-10-15
CVE-2018-1747 [HIGH] CWE-611 CVE-2018-1747: IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Inj IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.
nvd
CVE-2018-1744P3MEDIUMCVSS 6.5≥ 2.5.0, ≤ 2.5.0.9≥ 2.6.0, ≤ 2.6.0.4+6 more2018-10-15
CVE-2018-1744 [MEDIUM] CWE-22 CVE-2018-1744: IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148423.
nvd
CVE-2019-4565P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.2≥ 3.0.1, ≤ 3.0.1.1+2 more2019-09-20
CVE-2019-4565 [HIGH] CWE-521 CVE-2019-4565: IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong pass IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166626.
nvd
CVE-2021-38983P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38983 [HIGH] CWE-326 CVE-2021-38983: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
nvd
CVE-2021-38984P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-15
CVE-2021-38984 [HIGH] CWE-326 CVE-2021-38984: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
nvd
CVE-2016-6098P3HIGHCVSS 8.1v2.5.0.0v2.5.0.1+12 more2017-06-08
CVE-2016-6098 [HIGH] CWE-284 CVE-2016-6098: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical r IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
nvd
CVE-2018-1750P3HIGHCVSS 8.1≥ 2.6.0, ≤ 2.6.0.5≥ 2.7.0, ≤ 2.7.0.4+2 more2018-10-08
CVE-2018-1750 [HIGH] CWE-732 CVE-2018-1750: IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a w IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 148511.
nvd
Ibm Security Key Lifecycle Manager vulnerabilities | cvebase