PT-2017-8893 · Ibm · Ibm Tivoli Key Lifecycle Manager

Published

2017-02-07

·

Updated

2017-02-09

·

CVE-2016-6097

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Key Lifecycle Manager versions 2.0.1, 2.5, and 2.6
Description The issue allows web pages to be stored locally, which can then be read by another user on the system, potentially leading to information disclosure.
Recommendations For version 2.0.1, update the configuration to restrict local storage of web pages. For version 2.5, consider implementing access controls to limit which users can read locally stored web pages. For version 2.6, restrict access to sensitive web pages to prevent unauthorized reading.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6097

Affected Products

Ibm Tivoli Key Lifecycle Manager