VYPR

Tivoli Key Lifecycle Manager

Sign in to watch

by IBM

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-6096Med0.406.10.00Feb 7, 2017IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2016-6092Med0.406.20.00Feb 7, 2017IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
CVE-2016-6094Med0.284.30.00Feb 7, 2017IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
CVE-2016-6097Med0.264.00.00Feb 7, 2017IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.