Ibm Tivoli Key Lifecycle Manager vulnerabilities
6 known vulnerabilities affecting ibm/tivoli_key_lifecycle_manager.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2016-6093CRITICALCVSS 9.8v2.0.1v2.0.1.1+7 more2017-06-08
CVE-2016-6093 [CRITICAL] CWE-255 CVE-2016-6093: IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
nvd
CVE-2016-6098HIGHCVSS 8.1v2.0.1v2.0.1.1+7 more2017-06-08
CVE-2016-6098 [HIGH] CWE-284 CVE-2016-6098: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical r
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
nvd
CVE-2016-6092MEDIUMCVSS 6.2v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6092 [MEDIUM] CWE-200 CVE-2016-6092: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
nvd
CVE-2016-6094MEDIUMCVSS 4.3v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6094 [MEDIUM] CWE-200 CVE-2016-6094: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensit
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
nvd
CVE-2016-6096MEDIUMCVSS 6.1v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6096 [MEDIUM] CWE-79 CVE-2016-6096: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vul
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-6097MEDIUMCVSS 4.0v2.0.1v2.0.1.1+7 more2017-02-07
CVE-2016-6097 [MEDIUM] CWE-200 CVE-2016-6097: IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
nvd