cbcvebase.

Ibm Security Key Lifecycle Manager vulnerabilities

70 known vulnerabilities affecting ibm/security_key_lifecycle_manager.

Total CVEs
70
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM41LOW4

Vulnerabilities

Page 4 of 4
CVE-2023-25687P4MEDIUMCVSS 4.3v3.0v3.0.1+4 more2023-03-21
CVE-2023-25687 [MEDIUM] CWE-209 CVE-2023-25687: IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authentic IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
nvd
CVE-2018-1753P4MEDIUMCVSS 4.3≥ 2.6.0, ≤ 2.6.0.4≥ 2.7.0, ≤ 2.7.0.3+4 more2018-10-08
CVE-2018-1753 [MEDIUM] CWE-200 CVE-2018-1753: IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitiv IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.
nvd
CVE-2017-1727P4MEDIUMCVSS 4.3v2.5.0.0v2.5.0.1+17 more2018-01-04
CVE-2017-1727 [MEDIUM] CWE-532 CVE-2017-1727: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.
nvd
CVE-2016-6094P4MEDIUMCVSS 4.3v2.5.0.0v2.5.0.1+9 more2017-02-07
CVE-2016-6094 [MEDIUM] CWE-200 CVE-2016-6094: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensit IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
nvd
CVE-2014-0872P4MEDIUMCVSS 4.1v2.5.02018-04-25
CVE-2014-0872 [MEDIUM] CWE-200 CVE-2014-0872: The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, w The installation process in IBM Security Key Lifecycle Manager 2.5 stores unencrypted credentials, which might allow local users to obtain sensitive information by leveraging root access. IBM X-Force ID: 90988.
nvd
CVE-2016-6097P4MEDIUMCVSS 4.0v2.5.0.0v2.5.0.1+9 more2017-02-07
CVE-2016-6097 [MEDIUM] CWE-200 CVE-2016-6097: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
nvd
CVE-2016-6102P4LOWCVSS 3.7v2.5.0v2.5.0.0+10 more2017-03-27
CVE-2016-6102 [LOW] CWE-200 CVE-2016-6102: IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This ma IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.
nvd
CVE-2017-1669P4LOWCVSS 3.7v2.5.0.0v2.5.0.1+17 more2018-01-04
CVE-2017-1669 [LOW] CWE-200 CVE-2017-1669: IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. T IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.
nvd
CVE-2021-38973P4LOWCVSS 2.7≥ 3.0, ≤ 3.0.0.4≥ 3.0.1, ≤ 3.0.1.5+10 more2021-11-12
CVE-2021-38973 [LOW] CWE-20 CVE-2021-38973: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not va IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
nvd
CVE-2020-4846P4LOWCVSS 2.7≥ 3.0.1, < 3.0.1.5≥ 4.0, < 4.0.0.2+2 more2020-12-17
CVE-2020-4846 [LOW] CWE-209 CVE-2020-4846: IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive i IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190290.
nvd
Ibm Security Key Lifecycle Manager vulnerabilities | cvebase