First published: Thu Nov 11 2021(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212791.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | <=3.0 - 3.0.0.4 | |
Ibm Security Key Lifecycle Manager | <=3.0.1 - 3.0.1.5 | |
Ibm Security Key Lifecycle Manager | <=4.0 - 4.0.0.3 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.0 - 4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.0 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.1 | |
Ibm Security Key Lifecycle Manager | >=3.0<=3.0.0.4 | |
Ibm Security Key Lifecycle Manager | >=3.0.1<=3.0.1.5 | |
Ibm Security Key Lifecycle Manager | >=4.0<=4.0.0.3 | |
Ibm Security Key Lifecycle Manager | =4.1.0 | |
Ibm Security Key Lifecycle Manager | =4.1.0.1 | |
Ibm Security Key Lifecycle Manager | =4.1.1 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38982 is a vulnerability in IBM Tivoli Key Lifecycle Manager that allows cross-site scripting, potentially leading to credentials disclosure.
IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, and 4.1 are affected.
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, altering its intended functionality.
The severity of CVE-2021-38982 is medium, with a CVSS score of 5.4.
You can find more information about CVE-2021-38982 at the following links: - IBM X-Force Exchange: [https://exchange.xforce.ibmcloud.com/vulnerabilities/212791](https://exchange.xforce.ibmcloud.com/vulnerabilities/212791) - IBM Support Pages: [https://www.ibm.com/support/pages/node/6516042](https://www.ibm.com/support/pages/node/6516042)