CVE-2021-38973

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*

History

16 Nov 2021, 16:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 2.7
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/212778 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/212778 - VDB Entry, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6515528 - (CONFIRM) https://www.ibm.com/support/pages/node/6515528 - Patch, Vendor Advisory
CPE cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*
CWE CWE-20

12 Nov 2021, 16:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-12 16:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-38973

Mitre link : CVE-2021-38973

CVE.ORG link : CVE-2021-38973


JSON object : View

Products Affected

ibm

  • security_guardium_key_lifecycle_manager
  • security_key_lifecycle_manager
CWE
CWE-20

Improper Input Validation