PT-2017-8894 · Ibm · Ibm Tivoli Key Lifecycle Manager
Published
2017-06-08
·
Updated
2017-06-13
·
CVE-2016-6098
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Key Lifecycle Manager versions 2.0.1, 2.5, 2.6
Description
The issue allows a security-critical resource to be read or modified by unintended actors due to improper permission specifications.
Recommendations
For IBM Tivoli Key Lifecycle Manager version 2.0.1, update the permission settings to restrict access to the security-critical resource.
For IBM Tivoli Key Lifecycle Manager version 2.5, reconfigure the access controls to prevent unauthorized modification of the resource.
For IBM Tivoli Key Lifecycle Manager version 2.6, adjust the permission specifications to ensure the resource can only be accessed by intended actors.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Key Lifecycle Manager