CVE-2024-49816: IBM Security Guardium Key Lifecycle Manager information disclosure
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Other sources
IBM Security Guardium Key Lifecycle Manager stores potentially sensitive information in log files that could be read by a local privileged user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49816?
CVE-2024-49816 is considered a medium severity vulnerability due to the exposure of sensitive information in log files.
How do I fix CVE-2024-49816?
To fix CVE-2024-49816, you should upgrade to the latest version of IBM Security Guardium Key Lifecycle Manager that addresses this vulnerability.
Who is affected by CVE-2024-49816?
CVE-2024-49816 affects users of IBM Security Guardium Key Lifecycle Manager versions 4.1, 4.1.1, 4.2.0, and 4.2.1.
What information is stored insecurely in CVE-2024-49816?
CVE-2024-49816 potentially exposes sensitive information which is stored in log files accessible to privileged users.
Is there a workaround for CVE-2024-49816?
Currently, the recommended action for CVE-2024-49816 is to update to the fixed version as no specific workaround is provided.