First published: Tue Sep 24 2019(Updated: )
IBM Tivoli Key Lifecycle Manager stores user credentials in plain in clear text which can be read by a local user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | >=3.0<=3.0.0.2 | |
Ibm Security Key Lifecycle Manager | >=3.0.1<=3.0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4566 is medium.
CVE-2019-4566 affects IBM Tivoli Key Lifecycle Manager by storing user credentials in plain text, which can be read by a local user.
Versions 3.0 and 3.0.1 of IBM Security Key Lifecycle Manager are affected by CVE-2019-4566.
An attacker with local access can exploit CVE-2019-4566 by reading the user credentials stored in plain text.
Yes, IBM has released fixes for CVE-2019-4566. Please refer to IBM's support pages for more information.