PT-2017-8894 · Ibm · Ibm Tivoli Key Lifecycle Manager
Publicado
2017-06-08
·
Atualizado
2017-06-13
·
CVE-2016-6098
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Key Lifecycle Manager versions 2.0.1, 2.5, 2.6
Description
The issue allows a security-critical resource to be read or modified by unintended actors due to improper permission specifications.
Recommendations
For IBM Tivoli Key Lifecycle Manager version 2.0.1, update the permission settings to restrict access to the security-critical resource.
For IBM Tivoli Key Lifecycle Manager version 2.5, reconfigure the access controls to prevent unauthorized modification of the resource.
For IBM Tivoli Key Lifecycle Manager version 2.6, adjust the permission specifications to ensure the resource can only be accessed by intended actors.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Tivoli Key Lifecycle Manager