Ibm Security Key Lifecycle Manager vulnerabilities
70 known vulnerabilities affecting ibm/security_key_lifecycle_manager.
Total CVEs
70
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM41LOW4
Vulnerabilities
Page 2 of 4
CVE-2018-1751P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.2v3.0+1 more2019-01-23
CVE-2018-1751 [HIGH] CWE-326 CVE-2018-1751: IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algor
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512.
nvd
CVE-2021-38979P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38979 [HIGH] CWE-916 CVE-2021-38979: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
nvd
CVE-2023-25923P3HIGHCVSS 7.5v3.0v3.0.1+4 more2023-03-21
CVE-2023-25923 [HIGH] CWE-863 CVE-2023-25923: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
nvd
CVE-2017-1672P3HIGHCVSS 8.8v2.6.0v2.6.0.1+7 more2018-01-04
CVE-2017-1672 [HIGH] CWE-352 CVE-2017-1672: IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.
nvd
CVE-2016-6103P3HIGHCVSS 8.8v2.5.0v2.5.0.0+10 more2017-02-02
CVE-2016-6103 [HIGH] CWE-352 CVE-2016-6103: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2018-1738P4HIGHCVSS 7.1≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-11
CVE-2018-1738 [HIGH] CWE-287 CVE-2018-1738: IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.
nvd
CVE-2020-4569P4MEDIUMCVSS 6.5v3.0.1v4.02020-07-29
CVE-2020-4569 [MEDIUM] CVE-2020-4569: IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existe
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism. IBM X-Force ID: 184158.
nvd
CVE-2021-38975P4MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38975 [MEDIUM] CVE-2021-38975: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to ob
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
nvd
CVE-2018-1749P4MEDIUMCVSS 6.5≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1749 [MEDIUM] CVE-2018-1749: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.
nvd
CVE-2023-25688P4MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-22
CVE-2023-25688 [MEDIUM] CWE-22 CVE-2023-25688: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote atta
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606.
nvd
CVE-2023-25689P4MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-21
CVE-2023-25689 [MEDIUM] CWE-22 CVE-2023-25689: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote at
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618.
nvd
CVE-2019-4515P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 3.0.0.2≥ 3.0.1, ≤ 3.0.1.1+2 more2019-09-24
CVE-2019-4515 [MEDIUM] CWE-352 CVE-2019-4515: IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which c
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.
nvd
CVE-2018-1741P4MEDIUMCVSS 6.5≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1741 [MEDIUM] CVE-2018-1741: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency o
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.
nvd
CVE-2021-38974P4MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38974 [MEDIUM] CVE-2021-38974: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.
nvd
CVE-2021-38978P4MEDIUMCVSS 5.9≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38978 [MEDIUM] CWE-319 CVE-2021-38978: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain se
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
nvd
CVE-2017-1664P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+18 more2018-01-04
CVE-2017-1664 [MEDIUM] CWE-326 CVE-2017-1664: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithm
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
nvd
CVE-2017-1665P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+18 more2018-01-04
CVE-2017-1665 [MEDIUM] CWE-326 CVE-2017-1665: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithm
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
nvd
CVE-2016-6116P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+10 more2017-02-02
CVE-2016-6116 [MEDIUM] CWE-200 CVE-2016-6116: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive infor
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2016-6117P4MEDIUMCVSS 5.3v2.5.0v2.5.0.0+10 more2017-02-01
CVE-2016-6117 [MEDIUM] CWE-200 CVE-2016-6117: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can dis
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
nvd
CVE-2020-4573P4MEDIUMCVSS 5.3v3.0.1v4.02020-07-29
CVE-2020-4573 [MEDIUM] CVE-2020-4573: IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to respondin
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.
nvd