CVE-2024-49819: IBM Security Guardium Key Lifecycle Manager information disclosure
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
Other sources
IBM Security Guardium Key Lifecycle Manager could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49819?
CVE-2024-49819 is classified as a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-49819?
To address CVE-2024-49819, it is recommended to update IBM Security Guardium Key Lifecycle Manager to the latest version that addresses this vulnerability.
Which versions are affected by CVE-2024-49819?
CVE-2024-49819 affects IBM Security Guardium Key Lifecycle Manager versions 4.1, 4.1.1, 4.2.0, and 4.2.1.
What type of attack can exploit CVE-2024-49819?
CVE-2024-49819 can be exploited by remote attackers who can sniff communications to obtain sensitive cleartext information.
Is there a workaround for CVE-2024-49819?
Currently, the best approach to mitigate CVE-2024-49819 is to upgrade to a patched version of IBM Security Guardium Key Lifecycle Manager.