CVE-2021-38978: Medium severity IBM Security Key Lifecycle Manager vulnerability
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 212783.
Other sources
IBM Tivoli Key Lifecycle Manager could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-38978?
CVE-2021-38978 is a vulnerability in IBM Tivoli Key Lifecycle Manager that could allow a remote attacker to obtain sensitive information.
What is the severity of CVE-2021-38978?
The severity of CVE-2021-38978 is medium with a severity value of 5.9.
How does CVE-2021-38978 affect IBM Tivoli Key Lifecycle Manager?
CVE-2021-38978 affects IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, and 4.1.
How can a remote attacker exploit CVE-2021-38978?
A remote attacker can exploit CVE-2021-38978 by using man-in-the-middle techniques to obtain sensitive information.
Are there any references available for CVE-2021-38978?
Yes, you can find references for CVE-2021-38978 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/212783) and [Reference 2](https://www.ibm.com/support/pages/node/6516050).