Ibm Tivoli Key Lifecycle Manager vulnerabilities

6 known vulnerabilities affecting ibm/tivoli_key_lifecycle_manager.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2016-6093CRITICALCVSS 9.8v2.0.1v2.0.1.1+7 more2017-06-08
CVE-2016-6093 [CRITICAL] CWE-255 CVE-2016-6093: IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
nvd
CVE-2016-6098HIGHCVSS 8.1v2.0.1v2.0.1.1+7 more2017-06-08
CVE-2016-6098 [HIGH] CWE-284 CVE-2016-6098: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical r IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
nvd
CVE-2016-6092MEDIUMCVSS 6.2v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6092 [MEDIUM] CWE-200 CVE-2016-6092: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
nvd
CVE-2016-6094MEDIUMCVSS 4.3v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6094 [MEDIUM] CWE-200 CVE-2016-6094: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensit IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
nvd
CVE-2016-6096MEDIUMCVSS 6.1v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6096 [MEDIUM] CWE-79 CVE-2016-6096: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vul IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6097MEDIUMCVSS 4.0v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6097 [MEDIUM] CWE-200 CVE-2016-6097: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
nvd