Impact
Multiple vulnerabilities have been identified in IBM Guardium Key Lifecycle Manager versions 4.1 through 5.1. The CVE record specifies the affected releases as 4.1, 4.1.1, 4.2, 4.2.1, 5.0 and 5.1, and the associated CWE‑269 indicates a weakness in privilege management. The description and vendor advisory do not provide explicit details about the technical implementation of the flaws, but the CWE tag implies that an attacker might be able to misuse or bypass the intended access controls for key‑management operations.
Affected Systems
The affected product is IBM Guardium Key Lifecycle Manager. Versions impacted include 4.1.0, 4.1.1, 4.2.0, 4.2.1, 5.0.0, and 5.1.0, as well as all corresponding 4.x and 5.x sub‑versions identified in the supplied CPE strings.
Risk and Exploitability
The CVSS base score of 4.8 indicates a moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because no attack vector is specified in the CVE data, the likely exploitation path is inferred from the CWE‑269 association and would require some form of authenticated or elevated access to the Key Lifecycle Manager service.
OpenCVE Enrichment