Security Key Lifecycle Manager

Vendor:

First CVE: Feb 1, 2017 · Active for 9 years

70
Total CVEs
More Total CVEs than 98% of tracked products
11.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Key Lifecycle Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Mar 22, 2023
1,220 days ago

CVE Severity & Scoring

Security Key Lifecycle Manager70 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local8 (11.4%)
Network62 (88.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (90.0%)
High7 (10.0%)
Unknown0 (0.0%)
User Interaction
None60 (85.7%)
Unknown0 (0.0%)
Required10 (14.3%)
Privileges Required
Low22 (31.4%)
High4 (5.7%)
None44 (62.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which cou
Mar 21, 20239.831NONO
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Jun 8, 20179.831NONO
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Feb 2, 20179.831NONO
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fro
Feb 2, 20178.828NONO
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbo
Oct 8, 20189.327NONO
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to
Jan 9, 20189.827NONO
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.
Feb 1, 20178.227NONO
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper
Mar 22, 20238.826NONO
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended
Jun 8, 20178.126NONO
IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM
Jan 23, 20197.525NONO

Exploit Exposure

Signals from CVEs in this product scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (70 CVEs).

Media Mentions

Signals from CVEs in this product scope (70 CVEs).

Top CNAs Publishing CVEs For Security Key Lifecycle Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.1166.30.7%00
4.1.0.196.00.8%00
4.1.096.00.8%00
4.176.60.6%00
4.0136.71.0%00
3.0.1136.71.0%00
3.0.0.118.10.7%00
3.096.70.6%00
2.7.0.2106.61.2%00
2.7.0.1106.61.2%00
2.7.0106.61.2%00
2.6.0.3106.61.2%00
2.6.0.2246.61.2%00
2.6.0.1246.61.2%00
2.6.0.066.40.9%00
2.6.0186.71.4%00
2.5.0.896.41.3%00
2.5.0.7236.51.3%00
2.5.0.6236.51.3%00
2.5.0.5236.51.3%00