Show filters
53 Total Results
Displaying 21-30 of 53
Sort by:
Attacker Value
Unknown

CVE-2021-38984

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
Attacker Value
Unknown

CVE-2021-38976

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
Attacker Value
Unknown

CVE-2021-38978

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
Attacker Value
Unknown

CVE-2021-38979

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.
Attacker Value
Unknown

CVE-2021-38981

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788.
Attacker Value
Unknown

CVE-2021-38983

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.
Attacker Value
Unknown

CVE-2021-38982

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
Attacker Value
Unknown

CVE-2021-38975

Disclosure Date: November 12, 2021 (last updated October 07, 2023)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.
Attacker Value
Unknown

CVE-2021-38985

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attacker Value
Unknown

CVE-2021-38972

Disclosure Date: November 11, 2021 (last updated February 23, 2025)
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.