Security Key Lifecycle Manager
Vendor:
First CVE: Feb 1, 2017 · Active for 9 years
70
Total CVEs
More Total CVEs than 98% of tracked products
11.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Key Lifecycle Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Mar 22, 2023
1,220 days ago
CVE Severity & Scoring
Security Key Lifecycle Manager70 CVEs
59%
27%
9%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (11.4%)
Network62 (88.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (90.0%)
High7 (10.0%)
Unknown0 (0.0%)
User Interaction
None60 (85.7%)
Unknown0 (0.0%)
Required10 (14.3%)
Privileges Required
Low22 (31.4%)
High4 (5.7%)
None44 (62.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25684CRITICAL IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which cou | Mar 21, 2023 | 9.8 | 31 | NO | NO |
CVE-2016-6093CRITICAL IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | Jun 8, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-6095CRITICAL IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | Feb 2, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-6103HIGH IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fro | Feb 2, 2017 | 8.8 | 28 | NO | NO |
CVE-2018-1742CRITICAL IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbo | Oct 8, 2018 | 9.3 | 27 | NO | NO |
CVE-2017-1670CRITICAL IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to | Jan 9, 2018 | 9.8 | 27 | NO | NO |
CVE-2016-6105HIGH IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. | Feb 1, 2017 | 8.2 | 27 | NO | NO |
CVE-2023-25924HIGH IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper | Mar 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2016-6098HIGH IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended | Jun 8, 2017 | 8.1 | 26 | NO | NO |
CVE-2018-1751HIGH IBM Security Key Lifecycle Manager 3.0 through 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM | Jan 23, 2019 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (70 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (70 CVEs).
Media Mentions
Signals from CVEs in this product scope (70 CVEs).
Top CNAs Publishing CVEs For Security Key Lifecycle Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.1 | 16 | 6.3 | 0.7% | 0 | 0 |
| 4.1.0.1 | 9 | 6.0 | 0.8% | 0 | 0 |
| 4.1.0 | 9 | 6.0 | 0.8% | 0 | 0 |
| 4.1 | 7 | 6.6 | 0.6% | 0 | 0 |
| 4.0 | 13 | 6.7 | 1.0% | 0 | 0 |
| 3.0.1 | 13 | 6.7 | 1.0% | 0 | 0 |
| 3.0.0.1 | 1 | 8.1 | 0.7% | 0 | 0 |
| 3.0 | 9 | 6.7 | 0.6% | 0 | 0 |
| 2.7.0.2 | 10 | 6.6 | 1.2% | 0 | 0 |
| 2.7.0.1 | 10 | 6.6 | 1.2% | 0 | 0 |
| 2.7.0 | 10 | 6.6 | 1.2% | 0 | 0 |
| 2.6.0.3 | 10 | 6.6 | 1.2% | 0 | 0 |
| 2.6.0.2 | 24 | 6.6 | 1.2% | 0 | 0 |
| 2.6.0.1 | 24 | 6.6 | 1.2% | 0 | 0 |
| 2.6.0.0 | 6 | 6.4 | 0.9% | 0 | 0 |
| 2.6.0 | 18 | 6.7 | 1.4% | 0 | 0 |
| 2.5.0.8 | 9 | 6.4 | 1.3% | 0 | 0 |
| 2.5.0.7 | 23 | 6.5 | 1.3% | 0 | 0 |
| 2.5.0.6 | 23 | 6.5 | 1.3% | 0 | 0 |
| 2.5.0.5 | 23 | 6.5 | 1.3% | 0 | 0 |