Security Guardium Key Lifecycle Manager

Vendor:

First CVE: Nov 12, 2021 · Active for 4 years

29
Total CVEs
More Total CVEs than 97% of tracked products
9.7
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Guardium Key Lifecycle Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2021
4 years ago
Most Recent CVE
Dec 17, 2024
588 days ago

CVE Severity & Scoring

Security Guardium Key Lifecycle Manager29 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local3 (10.3%)
Network26 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (93.1%)
High2 (6.9%)
Unknown0 (0.0%)
User Interaction
None26 (89.7%)
Unknown0 (0.0%)
Required3 (10.3%)
Privileges Required
Low13 (44.8%)
High3 (10.3%)
None13 (44.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack
Feb 29, 20248.225NONO
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containi
Dec 20, 20239.125NONO
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.
Dec 20, 20238.824NONO
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed
Feb 29, 20248.823NONO
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed w
Feb 28, 20248.823NONO
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software doe
Nov 15, 20217.523NONO
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a spe
Feb 28, 20248.822NONO
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I
Nov 15, 20217.522NONO
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that
Dec 17, 20247.521NONO
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
Dec 20, 20237.521NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Security Guardium Key Lifecycle Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2.154.90.3%00
4.2.054.90.3%00
4.1.1195.40.6%00
4.1.0.196.00.8%00
4.1.0145.60.6%00