Lucene search

K
ibmIBM3E408D7CCEFB5186322DD026AA1B7B84B244204DE79C9E4BF733EA1799B63ECB
HistoryJun 16, 2018 - 9:50 p.m.

Security Bulletin: IBM Security Key Lifecycle Manager is affected by exposure of sensitive information stored in URL parameters (CVE-2017-1669)

2018-06-1621:50:04
www.ibm.com
9

EPSS

0.001

Percentile

48.3%

Summary

IBM Security Key Lifecycle Manager stores sensitive information in URL parameter. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. The latest fixpack listed below addresses this issue.

Vulnerability Details

CVEID: CVE-2017-1669**
DESCRIPTION:** IBM Security Key Lifecycle Manager stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
CVSS Base Score: 3.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/133636 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Key Lifecycle Manager: v2.5 - 2.5.0.8

IBM Security Key Lifecycle Manager v2.6 - 2.6.0.3

IBM Security Key Lifecycle Manager: v2.7 - 2.7.0.2

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM Security Key Lifecycle Manager| 2.5 - 2.5.0.8| 2.5.0-ISS-SKLM-FP0009
IBM Security Key Lifecycle Manager| 2.6- 2.6.0.3| 2.6.0-ISS-SKLM-FP0004
IBM Security Key Lifecycle Manager| 2.7- 2.7.0.2| 2.7.0-ISS-SKLM-FP0003

Workarounds and Mitigations

None

EPSS

0.001

Percentile

48.3%

Related for 3E408D7CCEFB5186322DD026AA1B7B84B244204DE79C9E4BF733EA1799B63ECB