VYPR

Tivoli Key Lifecycle Manager

by IBM

CVEs (24)

  • CVE-2016-6094MedFeb 7, 2017
    risk 0.28cvss 4.3epss 0.01

    IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.

  • CVE-2016-6097MedFeb 7, 2017
    risk 0.26cvss 4.0epss 0.00

    IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2017-1669LowJan 4, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.

  • CVE-2016-6102LowMar 27, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.

Page 2 of 2