Page 13 of 76 results (0.014 seconds)

CVSS: 8.8EPSS: 0%CPEs: 7EXPL: 0

IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639. IBM Tivoli Key Lifecycle Manager 2.6 y 2.7 es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en el que la web confía. IBM X-Force ID: 133639. • http://www.ibm.com/support/docview.wss?uid=swg22012019 https://exchange.xforce.ibmcloud.com/vulnerabilities/133639 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 17EXPL: 0

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133640. IBM Tivoli Key Lifecycle Manager 2.5, 2.6 y 2.7 es vulnerable a ataques Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22012015 http://www.securityfocus.com/bid/102436 https://exchange.xforce.ibmcloud.com/vulnerabilities/133640 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 20EXPL: 0

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM Tivoli Key Lifecycle Manager no requiere que los usuarios tengan contraseñas seguras por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. • http://www.ibm.com/support/docview.wss?uid=swg21997956 http://www.securityfocus.com/bid/95985 https://exchange.xforce.ibmcloud.com/vulnerabilities/118172 • CWE-255: Credentials Management Errors •

CVSS: 8.1EPSS: 0%CPEs: 20EXPL: 0

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM Tivoli Key Lifecycle Manager versiones 2.0.1, 2.5 y 2.6 especifica permisos para un recurso crítico de seguridad de una manera que permite que el recurso sea leído o modificado por actores no deseados. • http://www.ibm.com/support/docview.wss?uid=swg21997958 http://www.securityfocus.com/bid/95982 https://exchange.xforce.ibmcloud.com/vulnerabilities/118254 • CWE-284: Improper Access Control •

CVSS: 4.3EPSS: 0%CPEs: 12EXPL: 0

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359. • http://www.ibm.com/support/docview.wss?uid=swg22000359 http://www.securityfocus.com/bid/96976 http://www.securitytracker.com/id/1038093 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •