Ibm Security Key Lifecycle Manager vulnerabilities
70 known vulnerabilities affecting ibm/security_key_lifecycle_manager.
Total CVEs
70
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM41LOW4
Vulnerabilities
Page 1 of 4
CVE-2023-25924HIGHCVSS 8.8v3.0v3.0.1+4 more2023-03-22
CVE-2023-25924 [MEDIUM] CWE-863 CVE-2023-25924: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authentic
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
cvelistv5nvd
CVE-2023-25688MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-22
CVE-2023-25688 [MEDIUM] CWE-22 CVE-2023-25688: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote atta
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606.
cvelistv5nvd
CVE-2023-25684CRITICALCVSS 9.8v3.0v3.0.1+4 more2023-03-21
CVE-2023-25684 [MEDIUM] CWE-89 CVE-2023-25684: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL inj
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597.
cvelistv5nvd
CVE-2023-25923HIGHCVSS 7.5v3.0v3.0.1+4 more2023-03-21
CVE-2023-25923 [LOW] CWE-863 CVE-2023-25923: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
cvelistv5nvd
CVE-2023-25687MEDIUMCVSS 4.3v3.0v3.0.1+4 more2023-03-21
CVE-2023-25687 [MEDIUM] CWE-209 CVE-2023-25687: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authentic
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
cvelistv5nvd
CVE-2023-25686MEDIUMCVSS 5.5v3.0v3.0.1+4 more2023-03-21
CVE-2023-25686 [MEDIUM] CWE-522 CVE-2023-25686: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.
cvelistv5nvd
CVE-2023-25689MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-21
CVE-2023-25689 [LOW] CWE-22 CVE-2023-25689: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote at
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618.
cvelistv5nvd
CVE-2021-38980MEDIUMCVSS 5.3≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-23
CVE-2021-38980 [MEDIUM] CWE-209 CVE-2021-38980: IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.
cvelistv5nvd
CVE-2021-38979HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38979 [HIGH] CWE-916 CVE-2021-38979: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
cvelistv5nvd
CVE-2021-38983HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38983 [HIGH] CWE-326 CVE-2021-38983: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
cvelistv5nvd
CVE-2021-38984HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-15
CVE-2021-38984 [HIGH] CWE-326 CVE-2021-38984: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic al
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
cvelistv5nvd
CVE-2021-38982MEDIUMCVSS 5.4≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38982 [MEDIUM] CWE-79 CVE-2021-38982: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. Thi
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
cvelistv5nvd
CVE-2021-38981MEDIUMCVSS 5.3≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38981 [MEDIUM] CWE-209 CVE-2021-38981: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain se
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788.
cvelistv5nvd
CVE-2021-38977MEDIUMCVSS 4.3≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38977 [MEDIUM] CWE-311 CVE-2021-38977: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on autho
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain t
cvelistv5nvd
CVE-2021-38976MEDIUMCVSS 5.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38976 [MEDIUM] CWE-522 CVE-2021-38976: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear tex
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
cvelistv5nvd
CVE-2021-38974MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38974 [MEDIUM] CVE-2021-38974: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.
cvelistv5nvd
CVE-2021-38978MEDIUMCVSS 5.9≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38978 [MEDIUM] CWE-319 CVE-2021-38978: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain se
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
cvelistv5nvd
CVE-2021-38975MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38975 [MEDIUM] CVE-2021-38975: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to ob
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
cvelistv5nvd
CVE-2021-38985MEDIUMCVSS 4.3≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-12
CVE-2021-38985 [MEDIUM] CWE-20 CVE-2021-38985: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cvelistv5nvd
CVE-2021-38972MEDIUMCVSS 4.3≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-12
CVE-2021-38972 [MEDIUM] CWE-20 CVE-2021-38972: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cvelistv5nvd
1 / 4Next →