PT-2018-14035 · Ibm · Ibm Security Key Lifecycle Manager

Chris Shepherd

+5

·

Published

2018-10-11

·

Updated

2020-08-24

·

CVE-2018-1745

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions IBM Security Key Lifecycle Manager versions 2.7 through 3.0
Description The issue allows an unauthenticated user to restart the SKLM server due to missing authentication.
Recommendations For versions 2.7 through 3.0, update to a version that includes authentication for restarting the SKLM server. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1745

Affected Products

Ibm Security Key Lifecycle Manager