CVE-2021-38984

HIGH

IBM Tivoli Key Lifecycle Manager <4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-326
Status published
Products (3)
ibm/security_guardium_key_lifecycle_manager 4.1.1
ibm/security_guardium_key_lifecycle_manager 4.1.0 - 4.1.0.1
ibm/security_key_lifecycle_manager 3.0 - 3.0.0.4
Published Nov 15, 2021
Tracked Since Feb 18, 2026