CVE-2018-1741
Last modified
CVE-2018-1741 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 does not properly limit the number or frequency of interaction which could be used to cause a denial of service, compromise program logic or other consequences. IBM X-Force ID: 148420.
Metrics
CVSS:3.0/A:L/AC:L/AV:N/C:N/I:L/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Key Lifecycle Manager | >= 2.6.0, <= 2.6.0.4 |
| Ibm | Security Key Lifecycle Manager | >= 2.7.0, <= 2.7.0.3 |
| Ibm | Security Key Lifecycle Manager | >= 3.0, <= 3.0.0.1 |
References
- http://www.ibm.com/support/docview.wss?uid=ibm10733425Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148420VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10733425Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148420VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1741?
How severe is CVE-2018-1741?
How do I fix CVE-2018-1741?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-17401The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 t…
- CVE-2018-17402The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 t…
- CVE-2018-17403The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 t…
- CVE-2018-17404The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 …
- CVE-2018-17407An issue was discovered in t1_check_unusual_charstring funct…
- CVE-2018-17408Stack-based buffer overflows in Zahir Accounting Enterprise …
- CVE-2018-17410Horus CMS allows SQL Injection, as demonstrated by a request…9.8
- CVE-2018-17411An XML External Entity (XXE) vulnerability exists in iWay Da…
- CVE-2018-17412zzcms v8.3 contains a SQL Injection vulnerability in /user/l…
- CVE-2018-17413XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiy…
- CVE-2018-17414zzcms v8.3 has a SQL injection in /user/jobmanage.php via th…
- CVE-2018-17415zzcms V8.3 has a SQL injection in /user/zs_elite.php via the…
Are you affected by CVE-2018-1741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
