Lucene search

K
ibmIBM4A8AA15DBA4F3A3194BB376C9CFE70B56D970F0C913D8D3C01A677CB11176B4A
HistoryJun 16, 2018 - 9:50 p.m.

Security Bulletin: IBM Security Key Lifecycle Manager is affected by weak password policy (CVE-2016-6093)

2018-06-1621:50:04
www.ibm.com
17

EPSS

0.003

Percentile

71.4%

Summary

IBM Security Key Lifecycle Manager addresses this issue where the product does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

Vulnerability Details

CVEID: CVE-2016-6093**
DESCRIPTION:** IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118172 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM Security Key Lifecycle Manager: v2.5 - 2.5.0.7

IBM Security Key Lifecycle Manager v2.6 - 2.6.0.2

IBM Tivoli Key Lifecycle Manager v2.0.1 - 2.0.1.8

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM Tivoli Key Lifecycle manager| 2.0.1 - 2.0.1.8| 2.0.1-ISS-TKLM-FP0009
IBM Security Key Lifecycle Manager| 2.5 - 2.5.0.7| 2.5.0-ISS-SKLM-FP0008
IBM Security Key Lifecycle Manager| 2.6- 2.6.0.2| 2.6.0-ISS-SKLM-FP0003

Workarounds and Mitigations

Users can set strong password.

EPSS

0.003

Percentile

71.4%

Related for 4A8AA15DBA4F3A3194BB376C9CFE70B56D970F0C913D8D3C01A677CB11176B4A