IBM Security Key Lifecycle Manager has this issue where the product discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Security Key Lifecycle Manager latest fixpacks mentioned below addresses this vulnerability…
CVEID: CVE-2016-6099**
DESCRIPTION:** IBM Tivoli Key Lifecycle Manager discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118255 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
IBM Security Key Lifecycle Manager: v2.5 - 2.5.0.7
IBM Security Key Lifecycle Manager v2.6 - 2.6.0.2
Product
| VRMF| Remediation/First Fix
—|—|—
IBM Security Key Lifecycle Manager| 2.5 - 2.5.0.7| 2.5.0-ISS-SKLM-FP0008
IBM Security Key Lifecycle Manager| 2.6- 2.6.0.2| 2.6.0-ISS-SKLM-FP0003
None