PT-2018-14022 · Ibm · Ibm Tivoli Key Lifecycle Manager

Chris Shepherd

+5

·

Publicado

2018-10-08

·

Atualizado

2019-10-09

·

CVE-2018-1742

CVSS v3.1

9.3

Crítica

VetorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Tivoli Key Lifecycle Manager versions 2.6 through 3.0
Description The issue concerns hard-coded credentials, such as a password or cryptographic key, used for inbound authentication, outbound communication to external components, or encryption of internal data.
Recommendations For versions 2.6 through 3.0, update the software to remove the hard-coded credentials, replacing them with secure, configurable authentication mechanisms.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1742

Produtos afetados

Ibm Tivoli Key Lifecycle Manager