CVE-2016-6093

EUVD-2016-7027
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_key_lifecycle_manager
2.5.0.0
ibmsecurity_key_lifecycle_manager
2.5.0.1
ibmsecurity_key_lifecycle_manager
2.5.0.2
ibmsecurity_key_lifecycle_manager
2.5.0.3
ibmsecurity_key_lifecycle_manager
2.5.0.4
ibmsecurity_key_lifecycle_manager
2.5.0.5
ibmsecurity_key_lifecycle_manager
2.5.0.6
ibmsecurity_key_lifecycle_manager
2.5.0.7
ibmsecurity_key_lifecycle_manager
2.6.0.0
ibmsecurity_key_lifecycle_manager
2.6.0.1
ibmsecurity_key_lifecycle_manager
2.6.0.2
ibmtivoli_key_lifecycle_manager
2.0.1
ibmtivoli_key_lifecycle_manager
2.0.1.1
ibmtivoli_key_lifecycle_manager
2.0.1.2
ibmtivoli_key_lifecycle_manager
2.0.1.3
ibmtivoli_key_lifecycle_manager
2.0.1.4
ibmtivoli_key_lifecycle_manager
2.0.1.5
ibmtivoli_key_lifecycle_manager
2.0.1.6
ibmtivoli_key_lifecycle_manager
2.0.1.7
ibmtivoli_key_lifecycle_manager
2.0.1.8
𝑥
= Vulnerable software versions
Common Weakness Enumeration