First published: Mon Oct 08 2018(Updated: )
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Key Lifecycle Manager | >=2.6.0<=2.6.0.4 | |
IBM Security Key Lifecycle Manager | >=2.7.0<=2.7.0.3 | |
IBM Security Key Lifecycle Manager | >=3.0<=3.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1749 is classified as a medium-severity vulnerability due to its impact on system and data integrity.
To fix CVE-2018-1749, it is recommended to upgrade to the latest version of IBM Tivoli Key Lifecycle Manager that addresses this vulnerability.
CVE-2018-1749 affects IBM Security Key Lifecycle Manager versions 2.6, 2.7, and 3.0 up to specified patch levels.
Exploiting CVE-2018-1749 can allow attackers to bypass application controls, directly impacting system operations and data integrity.
CVE-2018-1749 involves incomplete blacklisting for input validation within IBM Tivoli Key Lifecycle Manager.