VendorsIBMsecurity_key_lifecycle_manager4.1.1
Vulnerabilities

IBM Security Key Lifecycle Manager 4.1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-25684
IBM Security Key Lifecycle Manager SQL injection
Published 2023-03-21 · Modified
9.8EPSS 0.010
CVE-2023-25924
IBM Security Key Lifecycle Manager improper authorization
Published 2023-03-21 · Modified
8.8EPSS 0.004
CVE-2021-38983
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
Published 2021-11-15 · Modified
7.5EPSS 0.009
CVE-2021-38979
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
Published 2021-11-15 · Modified
7.5EPSS 0.007
CVE-2023-25923
IBM Security Key Lifecycle Manager denial of service
Published 2023-03-21 · Modified
7.5EPSS 0.007
CVE-2021-38974
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.
Published 2021-11-15 · Modified
6.5EPSS 0.010
CVE-2021-38975
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
Published 2021-11-15 · Modified
6.5EPSS 0.010
CVE-2021-38976
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
Published 2021-11-15 · Modified
6.2EPSS 0.002
CVE-2023-25686
IBM Security Key Lifecycle Manager information disclosure
Published 2023-03-21 · Modified
6.2EPSS 0.002
CVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
Published 2021-11-15 · Modified
5.9EPSS 0.009
CVE-2021-38982
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
Published 2021-11-15 · Modified
5.4EPSS 0.005
CVE-2021-38981
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788.
Published 2021-11-15 · Modified
5.3EPSS 0.014
CVE-2023-25688
IBM Security Key Lifecycle Manager information disclosure
Published 2023-03-21 · Modified
5.3EPSS 0.009
CVE-2023-25689
IBM Security Key Lifecycle Manager information disclosure
Published 2023-03-21 · Modified
5.3EPSS 0.007
CVE-2021-38977
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 212782.
Published 2021-11-15 · Modified
4.3EPSS 0.005
CVE-2023-25687
IBM Security Key Lifecycle Manager information disclosure
Published 2023-03-21 · Modified
4.3EPSS 0.005