Lucene search

K
ibmIBM4AD8BE1BD6218C69CECEB55ED6DC57F13F50AB2EC7E21235607510BE0FD8EC78
HistoryOct 04, 2018 - 3:15 p.m.

Security Bulletin: IBM Security Key Lifecycle Manager is vulnerable to Improper Control of Interaction Frequency (CVE-2018-1741)

2018-10-0415:15:01
www.ibm.com
9

EPSS

0.001

Percentile

32.4%

Summary

IBM Security Key Lifecycle Manager does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences.

Vulnerability Details

CVEID: CVE-2018-1741 DESCRIPTION: IBM Tivoli Key Lifecycle Manager does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences.
CVSS Base Score: 6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/148420&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)

Affected Products and Versions

IBM Security Key Lifecycle Manager v2.6 - 2.6.0.4

IBM Security Key Lifecycle Manager: v2.7 - 2.7.0.3

IBM Security Key Lifecycle Manager: v3.0- 3.0.0.1

Remediation/Fixes

IBM Security Key Lifecycle Manager 2.6 - 2.6.0.4 2.6.0-ISS-SKLM-FP0005
IBM Security Key Lifecycle Manager 2.7- 2.7.0.3 2.7.0-ISS-SKLM-FP0004
IBM Security Key Lifecycle Manager 3.0- 3.0.0.1 3.0.0-ISS-SKLM-FP0002

EPSS

0.001

Percentile

32.4%

Related for 4AD8BE1BD6218C69CECEB55ED6DC57F13F50AB2EC7E21235607510BE0FD8EC78