Lucene search

K
ibmIBM039A0D52141096BA65A352F59DE310656C6A983F9097A0321A46FA9B4C294AAB
HistoryJun 16, 2018 - 9:49 p.m.

Security Bulletin: IBM Security Key Lifecycle Manager is affected by exposure of sensitive data due to missing HTTP Strict-Transport-Security Header (CVE-2016-6116)

2018-06-1621:49:58
www.ibm.com
17

EPSS

0.001

Percentile

49.2%

Summary

IBM Security Key Lifecycle Manager is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM Security Key Lifecycle Manager addresses this vulnerability with this CVE-2016-6116.

Vulnerability Details

CVEID: CVE-2016-6116**
DESCRIPTION:** IBM Tivoli Key Lifecycle Manager could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118354 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM Security Key Lifecycle Manager: v2.5 - 2.5.0.7

IBM Security Key Lifecycle Manager v2.6 - 2.6.0.2

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM Security Key Lifecycle Manager| 2.5 - 2.5.0.7| 2.5.0-ISS-SKLM-FP0008
IBM Security Key Lifecycle Manager| 2.6- 2.6.0.2| 2.6.0-ISS-SKLM-FP0003

Workarounds and Mitigations

None

EPSS

0.001

Percentile

49.2%

Related for 039A0D52141096BA65A352F59DE310656C6A983F9097A0321A46FA9B4C294AAB