CVE-2024-49817: IBM Security Guardium Key Lifecycle Manager information disclosure
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
Other sources
IBM Security Guardium Key Lifecycle Manager stores user credentials in configuration files which can be read by a local privileged user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49817?
CVE-2024-49817 is classified as a high severity vulnerability due to the exposure of user credentials.
How do I fix CVE-2024-49817?
To resolve CVE-2024-49817, update IBM Security Guardium Key Lifecycle Manager to version 4.2.2 or later, which addresses the credential storage issue.
Who is affected by CVE-2024-49817?
CVE-2024-49817 affects all versions of IBM Security Guardium Key Lifecycle Manager from 4.1 to 4.2.1.
What type of vulnerability is CVE-2024-49817?
CVE-2024-49817 is classified as a security misconfiguration vulnerability related to improper handling of user credentials.
Can local users exploit CVE-2024-49817?
Yes, local privileged users can exploit CVE-2024-49817 by accessing configuration files that contain sensitive user credentials.