IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
2024-12-17T18:15:23.937
2025-01-07T17:23:31.817
Analyzed
CVSSv3.1: 4.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_guardium_key_lifecycle_manager | 4.1.0 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.1.1 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.2.0 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.2.1 | Yes |