CVE-2017-1664
UnknownEPSS 0.84%
Last modified
CVE-2017-1664 is a vulnerability of currently unknown severity. IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Key Lifecycle Manager | 2.5.0 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.0 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.1 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.2 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.3 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.4 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.5 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.6 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.7 |
| Ibm | Security Key Lifecycle Manager | 2.5.0.8 |
| Ibm | Security Key Lifecycle Manager | 2.6.0 |
| Ibm | Security Key Lifecycle Manager | 2.6.0.1 |
| Ibm | Security Key Lifecycle Manager | 2.6.0.2 |
| Ibm | Security Key Lifecycle Manager | 2.6.0.3 |
| Ibm | Security Key Lifecycle Manager | 2.7.0 |
| Ibm | Security Key Lifecycle Manager | 2.7.0.1 |
| Ibm | Security Key Lifecycle Manager | 2.7.0.2 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22012027Vendor Advisory
- http://www.securityfocus.com/bid/102470Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/133557VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22012027Vendor Advisory
- http://www.securityfocus.com/bid/102470Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/133557VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1664?
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.
How severe is CVE-2017-1664?
Severity scoring for CVE-2017-1664 is pending analysis. The EPSS model estimates a 0.84% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1664?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16634In Joomla! before 3.8.2, a bug allowed third parties to bypa…
- CVE-2017-16635In TinyWebGallery v2.4, an XSS vulnerability is located in t…
- CVE-2017-16636In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located…
- CVE-2017-16637In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11…
- CVE-2017-16638The Gentoo net-misc/vde package before version 2.3.2-r4 may …
- CVE-2017-16639Tor Browser on Windows before 8.0 allows remote attackers to…
- CVE-2017-16641lib/rrd.php in Cacti 1.1.27 allows remote authenticated admi…
- CVE-2017-16642In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.…
- CVE-2017-16643The parse_hid_report_descriptor function in drivers/input/ta…
- CVE-2017-16644The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-co…
- CVE-2017-16645The ims_pcu_get_cdc_union_desc function in drivers/input/mis…
- CVE-2017-16646drivers/media/usb/dvb-usb/dib0700_devices.c in the Linux ker…
Are you affected by CVE-2017-1664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
