Cryptographic Algorithm Flaw in IBM Tivoli Key Lifecycle Manager
CVE-2021-38983

4.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
15 November 2021

Summary

IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, and 4.1 are affected by a vulnerability stemming from the use of cryptographic algorithms that do not provide adequate security. This weakness can potentially allow unauthorized users to decrypt sensitive information, exposing critical data and undermining system integrity. Organizations utilizing affected versions are encouraged to review their security measures and implement mitigations.

Affected Version(s)

Security Key Lifecycle Manager 3.0

Security Key Lifecycle Manager 3.0.1

Security Key Lifecycle Manager 4.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.