
CVE-2023-25684 – IBM Security Key Lifecycle Manager SQL injection
https://notcve.org/view.php?id=CVE-2023-25684
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247597 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-25686 – IBM Security Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-25686
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247601 • CWE-522: Insufficiently Protected Credentials •

CVE-2023-25923 – IBM Security Key Lifecycle Manager denial of service
https://notcve.org/view.php?id=CVE-2023-25923
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247629 • CWE-863: Incorrect Authorization •

CVE-2023-25688 – IBM Security Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-25688
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247606 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-25687 – IBM Security Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-25687
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247602 • CWE-209: Generation of Error Message Containing Sensitive Information CWE-532: Insertion of Sensitive Information into Log File •

CVE-2023-25924 – IBM Security Key Lifecycle Manager improper authorization
https://notcve.org/view.php?id=CVE-2023-25924
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247630 • CWE-863: Incorrect Authorization •

CVE-2023-25689 – IBM Security Key Lifecycle Manager information disclosure
https://notcve.org/view.php?id=CVE-2023-25689
21 Mar 2023 — IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618. • https://exchange.xforce.ibmcloud.com/vulnerabilities/247618 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2021-38980
https://notcve.org/view.php?id=CVE-2021-38980
23 Nov 2021 — IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 212786. IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) versiones 3.0, 3.0.1, 4.0 y 4.1, podría permitir a un atacante remoto obtener información confidencial cu... • https://exchange.xforce.ibmcloud.com/vulnerabilities/212786 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2021-38984
https://notcve.org/view.php?id=CVE-2021-38984
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 212793 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212793 • CWE-326: Inadequate Encryption Strength •

CVE-2021-38983
https://notcve.org/view.php?id=CVE-2021-38983
15 Nov 2021 — IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792. IBM Tivoli Key Lifecycle Manager versiones 3.0, 3.0.1, 4.0 y 4.1, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 212792 • https://exchange.xforce.ibmcloud.com/vulnerabilities/212792 • CWE-326: Inadequate Encryption Strength •