IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7175067 |
History
Tue, 17 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Dec 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
Title | IBM Security Guardium Key Lifecycle Manager information disclosure | |
First Time appeared |
Ibm
Ibm security Guardium Key Lifecycle Manager |
|
Weaknesses | CWE-319 | |
CPEs | cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.2.1:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm security Guardium Key Lifecycle Manager |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2024-12-17T17:42:14.257Z
Updated: 2024-12-17T20:37:34.046Z
Reserved: 2024-10-20T13:40:37.121Z
Link: CVE-2024-49820
Vulnrichment
Updated: 2024-12-17T20:35:10.294Z
NVD
Status : Received
Published: 2024-12-17T18:15:24.463
Modified: 2024-12-17T18:15:24.463
Link: CVE-2024-49820
Redhat
No data.