First published: Thu Nov 11 2021(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Key Lifecycle Manager | >=4.1.0<=4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.1 | |
Ibm Security Key Lifecycle Manager | >=3.0<=3.0.0.4 | |
Ibm Security Key Lifecycle Manager | >=3.0.1<=3.0.1.5 | |
Ibm Security Key Lifecycle Manager | >=4.0<=4.0.0.3 | |
Ibm Security Key Lifecycle Manager | <=3.0 - 3.0.0.4 | |
Ibm Security Key Lifecycle Manager | <=3.0.1 - 3.0.1.5 | |
Ibm Security Key Lifecycle Manager | <=4.0 - 4.0.0.3 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.0 - 4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38984 is a vulnerability in IBM Tivoli Key Lifecycle Manager that allows an attacker to decrypt highly sensitive information.
IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, and 4.1 are affected.
The vulnerability in IBM Tivoli Key Lifecycle Manager can be exploited by using weaker than expected cryptographic algorithms.
The severity of CVE-2021-38984 is high with a CVSS score of 7.5.
IBM has provided a fix for the vulnerability in IBM Tivoli Key Lifecycle Manager. Please refer to the IBM support page for more information.