First published: Wed Jan 03 2018(Updated: )
IBM Tivoli Key Lifecycle Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Key Lifecycle Manager | =2.5.0 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.0 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.2 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.3 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.4 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.5 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.6 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.7 | |
IBM Security Guardium Key Lifecycle Manager | =2.5.0.8 | |
IBM Security Guardium Key Lifecycle Manager | =2.6.0 | |
IBM Security Guardium Key Lifecycle Manager | =2.6.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =2.6.0.2 | |
IBM Security Guardium Key Lifecycle Manager | =2.6.0.3 | |
IBM Security Guardium Key Lifecycle Manager | =2.7.0 | |
IBM Security Guardium Key Lifecycle Manager | =2.7.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =2.7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1673 is classified as medium due to the potential for cross-site scripting leading to credential disclosure.
To fix CVE-2017-1673, apply the latest patches and updates provided by IBM for affected versions of Tivoli Key Lifecycle Manager.
CVE-2017-1673 affects versions 2.5.0 through 2.7.0 of IBM Tivoli Key Lifecycle Manager.
CVE-2017-1673 can allow unauthorized users to inject malicious JavaScript into the Web UI, potentially compromising user credentials in a trusted session.
A potential workaround for CVE-2017-1673 is to limit user input in the Web UI to prevent the execution of arbitrary JavaScript.