First published: Fri Nov 06 2020(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184157.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | =3.0 | |
Ibm Security Key Lifecycle Manager | =3.0.1 | |
Ibm Security Key Lifecycle Manager | =4.0 | |
<=3.0.1 | ||
<=3.0 | ||
<=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4568 is medium.
IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, and 4.0 are affected by CVE-2020-4568.
The CWE ID of CVE-2020-4568 is 522.
A local user can read user credentials in clear text by accessing the storage where IBM Tivoli Key Lifecycle Manager stores them.
Yes, IBM has provided a security bulletin with information on how to mitigate the vulnerability.