Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Security_guardium_key_lifecycle_manager
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 29 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-11-15 | CVE-2021-38983 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792. | Security_guardium_key_lifecycle_manager, Security_key_lifecycle_manager | 7.5 | ||
2021-11-15 | CVE-2021-38984 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793. | Security_guardium_key_lifecycle_manager, Security_key_lifecycle_manager | 7.5 | ||
2021-11-23 | CVE-2021-38980 | IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786. | Security_guardium_key_lifecycle_manager, Security_key_lifecycle_manager | 5.3 | ||
2023-12-20 | CVE-2023-47704 | IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220. | Security_guardium_key_lifecycle_manager | 7.5 | ||
2023-12-20 | CVE-2023-47706 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. | Security_guardium_key_lifecycle_manager | 8.8 | ||
2023-12-20 | CVE-2023-47702 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196. | Security_guardium_key_lifecycle_manager | 9.1 | ||
2023-12-20 | CVE-2023-47705 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228. | Security_guardium_key_lifecycle_manager | 4.3 | ||
2023-12-20 | CVE-2023-47703 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197. | Security_guardium_key_lifecycle_manager | 5.3 | ||
2023-12-20 | CVE-2023-47707 | IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522. | Security_guardium_key_lifecycle_manager | 5.4 |