IBM Security Key Lifecycle Manager Vulnerability (CVE-2017-1669)
IBM Security Key Lifecycle Manager Vulnerability (CVE-2017-1669)
Release date:
Updated on:
Affected Systems:
IBM Tivoli Key Lifecycle Manager 2.7
IBM Tivoli Key Lifecycle Manager 2.6
IBM Tivoli Key Lifecycle Manager 2.5
Description:
Bugtraq id: 102468
CVE (CAN) ID: CVE-2017-1669
IBM Security Key Lifecycle Manager centrally, simplifies, and automatically performs encryption and Key management, helping users minimize risks and reduce operating costs.
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 save sensitive information in the URL parameters. If the unauthenticated party accesses the URL through server logs, reference headers, or browser history records, this vulnerability can cause information leakage.
<* Source: Ron Craig
Warren Moynihan
Dmitriy Beryoza
*>
Suggestion:
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ibm.com/
Http://www-01.ibm.com/support/docview.wss? Uid = swg21997955