CVE-2016-6093

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
ibmsecurity_key_lifecycle_manager
2.5.0.0
ibmsecurity_key_lifecycle_manager
2.5.0.1
ibmsecurity_key_lifecycle_manager
2.5.0.2
ibmsecurity_key_lifecycle_manager
2.5.0.3
ibmsecurity_key_lifecycle_manager
2.5.0.4
ibmsecurity_key_lifecycle_manager
2.5.0.5
ibmsecurity_key_lifecycle_manager
2.5.0.6
ibmsecurity_key_lifecycle_manager
2.5.0.7
ibmsecurity_key_lifecycle_manager
2.6.0.0
ibmsecurity_key_lifecycle_manager
2.6.0.1
ibmsecurity_key_lifecycle_manager
2.6.0.2
ibmtivoli_key_lifecycle_manager
2.0.1
ibmtivoli_key_lifecycle_manager
2.0.1.1
ibmtivoli_key_lifecycle_manager
2.0.1.2
ibmtivoli_key_lifecycle_manager
2.0.1.3
ibmtivoli_key_lifecycle_manager
2.0.1.4
ibmtivoli_key_lifecycle_manager
2.0.1.5
ibmtivoli_key_lifecycle_manager
2.0.1.6
ibmtivoli_key_lifecycle_manager
2.0.1.7
ibmtivoli_key_lifecycle_manager
2.0.1.8
𝑥
= Vulnerable software versions
Common Weakness Enumeration