CVE-2021-38972

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*

History

16 Nov 2021, 16:21

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (CONFIRM) https://www.ibm.com/support/pages/node/6515530 - (CONFIRM) https://www.ibm.com/support/pages/node/6515530 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/212775 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/212775 - VDB Entry, Vendor Advisory
CWE CWE-20

12 Nov 2021, 16:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-12 16:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-38972

Mitre link : CVE-2021-38972

CVE.ORG link : CVE-2021-38972


JSON object : View

Products Affected

ibm

  • security_guardium_key_lifecycle_manager
  • security_key_lifecycle_manager
CWE
CWE-20

Improper Input Validation