First published: Wed Nov 10 2021(Updated: )
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Guardium Key Lifecycle Manager | >=4.1.0<=4.1.0.1 | |
IBM Security Guardium Key Lifecycle Manager | =4.1.1 | |
Ibm Security Key Lifecycle Manager | >=3.0<=3.0.0.4 | |
Ibm Security Key Lifecycle Manager | >=3.0.1<=3.0.1.5 | |
Ibm Security Key Lifecycle Manager | >=4.0<=4.0.0.3 | |
<=3.0 - 3.0.0.4 | ||
<=3.0.1 - 3.0.1.5 | ||
<=4.0 - 4.0.0.3 | ||
<=4.1.0 - 4.1.0.1 | ||
<=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38985 is medium.
IBM Tivoli Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, and 4.1 are affected by CVE-2021-38985.
CVE-2021-38985 allows input data to be processed without proper validation, which can lead to potential security vulnerabilities in IBM Tivoli Key Lifecycle Manager.
IBM has provided fixes for the affected versions of IBM Tivoli Key Lifecycle Manager. Please refer to the IBM Security Bulletin for more information.
More information about CVE-2021-38985 can be found on the IBM X-Force Exchange and the IBM Support website.