cbcvebase.

Ibm Security Key Lifecycle Manager vulnerabilities

70 known vulnerabilities affecting ibm/security_key_lifecycle_manager.

Total CVEs
70
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM41LOW4

Vulnerabilities

Page 2 of 4
CVE-2018-1751P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.2v3.0+1 more2019-01-23
CVE-2018-1751 [HIGH] CWE-326 CVE-2018-1751: IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algor IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 148512.
nvd
CVE-2021-38979P3HIGHCVSS 7.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38979 [HIGH] CWE-916 CVE-2021-38979: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
nvd
CVE-2023-25923P3HIGHCVSS 7.5v3.0v3.0.1+4 more2023-03-21
CVE-2023-25923 [HIGH] CWE-863 CVE-2023-25923: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
nvd
CVE-2017-1672P3HIGHCVSS 8.8v2.6.0v2.6.0.1+7 more2018-01-04
CVE-2017-1672 [HIGH] CWE-352 CVE-2017-1672: IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.
nvd
CVE-2016-6103P3HIGHCVSS 8.8v2.5.0v2.5.0.0+10 more2017-02-02
CVE-2016-6103 [HIGH] CWE-352 CVE-2016-6103: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2018-1738P4HIGHCVSS 7.1≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-11
CVE-2018-1738 [HIGH] CWE-287 CVE-2018-1738: IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.
nvd
CVE-2020-4569P4MEDIUMCVSS 6.5v3.0.1v4.02020-07-29
CVE-2020-4569 [MEDIUM] CVE-2020-4569: IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existe IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism. IBM X-Force ID: 184158.
nvd
CVE-2021-38975P4MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38975 [MEDIUM] CVE-2021-38975: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to ob IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
nvd
CVE-2018-1749P4MEDIUMCVSS 6.5≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1749 [MEDIUM] CVE-2018-1749: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.
nvd
CVE-2023-25688P4MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-22
CVE-2023-25688 [MEDIUM] CWE-22 CVE-2023-25688: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote atta IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606.
nvd
CVE-2023-25689P4MEDIUMCVSS 5.3v3.0v3.0.1+4 more2023-03-21
CVE-2023-25689 [MEDIUM] CWE-22 CVE-2023-25689: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote at IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618.
nvd
CVE-2019-4515P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 3.0.0.2≥ 3.0.1, ≤ 3.0.1.1+2 more2019-09-24
CVE-2019-4515 [MEDIUM] CWE-352 CVE-2019-4515: IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which c IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.
nvd
CVE-2018-1741P4MEDIUMCVSS 6.5≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1741 [MEDIUM] CVE-2018-1741: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency o IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.
nvd
CVE-2021-38974P4MEDIUMCVSS 6.5≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38974 [MEDIUM] CVE-2021-38974: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.
nvd
CVE-2021-38978P4MEDIUMCVSS 5.9≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+11 more2021-11-15
CVE-2021-38978 [MEDIUM] CWE-319 CVE-2021-38978: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain se IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
nvd
CVE-2017-1664P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+18 more2018-01-04
CVE-2017-1664 [MEDIUM] CWE-326 CVE-2017-1664: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithm IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
nvd
CVE-2017-1665P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+18 more2018-01-04
CVE-2017-1665 [MEDIUM] CWE-326 CVE-2017-1665: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithm IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
nvd
CVE-2016-6116P4MEDIUMCVSS 5.9v2.5.0v2.5.0.0+10 more2017-02-02
CVE-2016-6116 [MEDIUM] CWE-200 CVE-2016-6116: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive infor IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
nvd
CVE-2016-6117P4MEDIUMCVSS 5.3v2.5.0v2.5.0.0+10 more2017-02-01
CVE-2016-6117 [MEDIUM] CWE-200 CVE-2016-6117: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can dis IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
nvd
CVE-2020-4573P4MEDIUMCVSS 5.3v3.0.1v4.02020-07-29
CVE-2020-4573 [MEDIUM] CVE-2020-4573: IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to respondin IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.
nvd
Ibm Security Key Lifecycle Manager vulnerabilities | cvebase