Lucene search

K
ibmIBM7220D511FC620F10435777D8793E807751170DFE7F6F872293BA8B144FB32F52
HistoryJun 16, 2018 - 9:51 p.m.

Security Bulletin: IBM Security Key Lifecycle Manager is affected by Query Parameter in SSL Request (CVE-2016-6102)

2018-06-1621:51:07
www.ibm.com
11

EPSS

0.001

Percentile

48.4%

Summary

IBM Security Key Lifecycle Manager allows storage of sensitive information in URLs.

Vulnerability Details

CVEID: CVE-2016-6102**
DESCRIPTION:** IBM Tivoli Key Lifecycle Manager stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
CVSS Base Score: 3.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118258 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Key Lifecycle Manager: v2.5 - 2.5.0.7

IBM Security Key Lifecycle Manager v2.6 - 2.6.0.2

Remediation/Fixes

Product

| VRMF| Remediation/First Fix
—|—|—
IBM Security Key Lifecycle Manager| 2.5 - 2.5.0.7| 2.5.0-ISS-SKLM-FP0008
IBM Security Key Lifecycle Manager| 2.6- 2.6.0.2| 2.6.0-ISS-SKLM-FP0003

Workarounds and Mitigations

None

EPSS

0.001

Percentile

48.4%

Related for 7220D511FC620F10435777D8793E807751170DFE7F6F872293BA8B144FB32F52