
CVE-2023-47706 – IBM Security Guardium Key Lifecycle Manager file upload
https://notcve.org/view.php?id=CVE-2023-47706
20 Dec 2023 — IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. IBM Security Guardium Key Lifecycle Manager 4.3 podría permitir que un usuario autenticado cargue archivos de un tipo de archivo peligroso. ID de IBM X-Force: 271341. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271341 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2023-47705 – IBM Security Guardium Key Lifecycle Manager improper input validation
https://notcve.org/view.php?id=CVE-2023-47705
20 Dec 2023 — IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228. IBM Security Guardium Key Lifecycle Manager 4.3 podría permitir que un usuario autenticado manipule los datos del nombre de usuario debido a una validación de entrada incorrecta. ID de IBM X-Force: 271228. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271228 • CWE-20: Improper Input Validation •

CVE-2023-47704 – IBM Security Guardium Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-47704
20 Dec 2023 — IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220. IBM Security Guardium Key Lifecycle Manager 4.3 contiene credenciales codificadas en texto plano u otros secretos en el repositorio de código fuente. ID de IBM X-Force: 271220. • https://exchange.xforce.ibmcloud.com/vulnerabilities/271220 • CWE-798: Use of Hard-coded Credentials •

CVE-2021-38980
https://notcve.org/view.php?id=CVE-2021-38980
23 Nov 2021 — IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786. IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) versiones 3.0, 3.0.1, 4.0 y 4.1, podría permitir a un atacante remoto obtener información confidencial cu... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212786 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2021-38984
https://notcve.org/view.php?id=CVE-2021-38984
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 212793 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212793 • CWE-326: Inadequate Encryption Strength •

CVE-2021-38983
https://notcve.org/view.php?id=CVE-2021-38983
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 212792 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212792 • CWE-326: Inadequate Encryption Strength •

CVE-2021-38982
https://notcve.org/view.php?id=CVE-2021-38982
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrari... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212791 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-38981
https://notcve.org/view.php?id=CVE-2021-38981
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212788. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, podría permitir a un atacante remoto obtener información confidencial cuando es devuelto un mensaje de error técnico detallado en el navegador. Esta información pod... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212788 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2021-38979
https://notcve.org/view.php?id=CVE-2021-38979
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, usa un hash criptográfico unidireccional contra una entrada que no debería ser reversible, como una contraseña, pero el software no usa también una salt como parte de la entrada. IBM X-Force ID: 212... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212785 • CWE-916: Use of Password Hash With Insufficient Computational Effort •

CVE-2021-38978
https://notcve.org/view.php?id=CVE-2021-38978
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, podría permitir a un atacante remoto obtener información confidencial, causado por el fallo en la habilitación inap... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212783 • CWE-319: Cleartext Transmission of Sensitive Information •