VendorsIBMsecurity_guardium_key_lifecycle_managerany version
Vulnerabilities

IBM Security Guardium Key Lifecycle Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-47702
IBM Security Guardium Key Lifecycle Manager directory traversal
Published 2023-12-20 · Modified
9.1EPSS 0.010
CVE-2023-25925
IBM Security Guardium Key Lifecycle Manager command injection
Published 2024-02-28 · Analyzed
8.8EPSS 0.014
CVE-2023-25921
IBM Security Guardium Key Lifecycle Manager file upload
Published 2024-02-29 · Analyzed
8.8EPSS 0.011
CVE-2023-47706
IBM Security Guardium Key Lifecycle Manager file upload
Published 2023-12-20 · Modified
8.8EPSS 0.008
CVE-2023-25922
IBM Security Guardium Key Lifecycle Manager file upload
Published 2024-02-28 · Analyzed
8.8EPSS 0.006
CVE-2023-25926
IBM Security Guardium Key Lifecycle Manager XML external entity injection
Published 2024-02-29 · Analyzed
8.2EPSS 0.014
CVE-2021-38984
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
Published 2021-11-15 · Modified
7.5EPSS 0.006
CVE-2023-47704
IBM Security Guardium Key Lifecycle Manager information disclosure
Published 2023-12-20 · Modified
7.5EPSS 0.006
CVE-2023-47707
IBM Security Guardium Key Lifecycle Manager cross-site scripting
Published 2023-12-20 · Modified
5.4EPSS 0.004
CVE-2021-38980
IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786.
Published 2021-11-23 · Modified
5.3EPSS 0.012
CVE-2023-47703
IBM Security Guardium Key Lifecycle Manager information disclosure
Published 2023-12-20 · Modified
5.3EPSS 0.008
CVE-2021-38972
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Published 2021-11-12 · Modified
4.3EPSS 0.006
CVE-2021-38985
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Published 2021-11-12 · Modified
4.3EPSS 0.006
CVE-2023-47705
IBM Security Guardium Key Lifecycle Manager improper input validation
Published 2023-12-20 · Modified
4.3EPSS 0.005
CVE-2021-38973
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Published 2021-11-12 · Modified
4.0EPSS 0.006