CVE-2024-49820: IBM Security Guardium Key Lifecycle Manager information disclosure
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Other sources
IBM Security Guardium Key Lifecycle Manager could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49820?
CVE-2024-49820 has a medium severity rating due to its potential to expose sensitive information.
How do I fix CVE-2024-49820?
To mitigate CVE-2024-49820, ensure that HTTP Strict Transport Security is properly enabled in IBM Security Guardium Key Lifecycle Manager.
Which versions are affected by CVE-2024-49820?
CVE-2024-49820 affects IBM Security Guardium Key Lifecycle Manager versions 4.1, 4.1.1, 4.2.0, and 4.2.1.
Can CVE-2024-49820 be exploited remotely?
Yes, CVE-2024-49820 can be exploited remotely by an attacker to obtain sensitive information.
What type of information could be exposed due to CVE-2024-49820?
CVE-2024-49820 could lead to the exposure of sensitive information due to improper security configurations.