PatchSiren cyber security CVE debrief
CVE-2016-6116 IBM CVE debrief
CVE-2016-6116 affects IBM Tivoli Key Lifecycle Manager 2.5 and 2.6. Because HTTP Strict Transport Security was not properly enabled, a remote attacker with a man-in-the-middle position could potentially expose sensitive information. The issue is categorized as information disclosure rather than code execution, but it still matters because it can weaken transport protections for web sessions and administrative access.
- Vendor
- IBM
- Product
- Security Key Lifecycle Manager
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-02
- Advisory updated
- 2026-05-13
Who should care
IBM Tivoli Key Lifecycle Manager administrators, teams operating the affected 2.5/2.6 builds, and security teams responsible for TLS/HTTPS hardening and certificate-based trust on management interfaces.
Technical summary
NVD describes the flaw as a failure to properly enable HTTP Strict Transport Security (HSTS). In practice, that means affected web traffic may not receive the downgrade protections HSTS is intended to provide, increasing exposure to active network interception or other man-in-the-middle attacks. The NVD record lists multiple vulnerable CPE entries across SKLM 2.5 and 2.6 maintenance builds, and the weakness is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
Defensive priority
Medium
Recommended defensive actions
- Confirm whether any IBM Tivoli Key Lifecycle Manager 2.5 or 2.6 instances are still in use and map them to the vulnerable maintenance builds listed by NVD.
- Apply the IBM patch/advisory referenced in the NVD record and verify that HSTS is enabled on the relevant HTTPS endpoints.
- Review reverse proxies, load balancers, and web server front ends to ensure HSTS headers are consistently enforced and not stripped before reaching clients.
- Check for any dependent administrative workflows that traverse untrusted networks and prioritize their remediation or network restriction.
- Retest the service after remediation to confirm HTTPS hardening is active and that clients receive the expected security headers.
Evidence notes
The description states that IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information because HTTP Strict Transport Security was not properly enabled, enabling man-in-the-middle techniques. The NVD metadata marks the issue as CVSS 3.0 5.9 (Medium) with CWE-200, and references an IBM vendor advisory/patch plus a third-party advisory entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6116 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6116
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6116 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6116
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.