First published: Wed Jul 29 2020(Updated: )
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | =3.0.1 | |
Ibm Security Key Lifecycle Manager | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4574 is high with a score of 7.5.
IBM Tivoli Key Lifecycle Manager does not require strong passwords by default.
The affected versions of IBM Tivoli Key Lifecycle Manager are 3.0.1 and 4.0.
Attackers can exploit CVE-2020-4574 to compromise user accounts by taking advantage of the weak password requirements.
There is no information available about a fix for CVE-2020-4574 at this time. It is recommended to follow the provided IBM reference links for updates and mitigation steps.