📦 Security Guardium Key Lifecycle Manager

by Ibm

🔍 What is Security Guardium Key Lifecycle Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-25921

HIGH CVSS 8.5 Feb 29, 2024

This vulnerability in IBM Security Guardium Key Lifecycle Manager allows attackers to upload dangerous file types that can be automatically processed within the product environment. This affects versi...

CVE-2023-25925

HIGH CVSS 8.5 Feb 28, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on IBM Security Guardium Key Lifecycle Manager systems by sending specially crafted requests. It...

CVE-2021-38983

HIGH CVSS 7.5 Nov 15, 2021

IBM Tivoli Key Lifecycle Manager versions 3.0 through 4.1 use weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects organizations using these versions...

CVE-2021-38979

HIGH CVSS 7.5 Nov 15, 2021

IBM Tivoli Key Lifecycle Manager versions 3.0 through 4.1 store passwords using unsalted cryptographic hashes, making them vulnerable to rainbow table and brute-force attacks. This affects organizatio...

CVE-2024-49818

MEDIUM CVSS 4.3 Dec 17, 2024

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 expose detailed technical error messages to remote attackers, potentially revealing sensitive system information. This informatio...

CVE-2024-49816

MEDIUM CVSS 4.9 Dec 17, 2024

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 store sensitive information in log files that could be read by local privileged users. This vulnerability allows attackers with l...