Vulnerability CVE-2018-1749


Published: 2018-10-08

Description:
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 148484.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
IBM -> Security key lifecycle manager 

 References:
http://www.ibm.com/support/docview.wss?uid=ibm10733303
https://exchange.xforce.ibmcloud.com/vulnerabilities/148484

Copyright 2024, cxsecurity.com

 

Back to Top