IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7175067 |
![]() ![]() |
History
Tue, 17 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Dec 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
Title | IBM Security Guardium Key Lifecycle Manager information disclosure | |
First Time appeared |
Ibm
Ibm security Guardium Key Lifecycle Manager |
|
Weaknesses | CWE-319 | |
CPEs | cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.2.1:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm security Guardium Key Lifecycle Manager |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2024-12-17T17:42:14.257Z
Updated: 2024-12-17T20:37:34.046Z
Reserved: 2024-10-20T13:40:37.121Z
Link: CVE-2024-49820

Updated: 2024-12-17T20:35:10.294Z

Status : Analyzed
Published: 2024-12-17T18:15:24.463
Modified: 2025-01-10T17:42:53.707
Link: CVE-2024-49820

No data.