IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
2024-12-17T18:15:24.127
2025-01-07T17:20:08.497
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_guardium_key_lifecycle_manager | 4.1.0 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.1.1 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.2.0 | Yes |
Application | ibm | security_guardium_key_lifecycle_manager | 4.2.1 | Yes |