PT-2023-20362 · Ibm · Ibm Security Guardium Key Lifecycle Manager

Ben Goodspeed

+8

·

Published

2023-03-21

·

Updated

2023-03-24

·

CVE-2023-25923

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Guardium Key Lifecycle Manager versions 3.0 through 4.1.1
Description The issue allows an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
Recommendations For versions 3.0 through 4.1.1, consider restricting file upload capabilities to authorized users as a temporary workaround until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-25923

Affected Products

Ibm Security Guardium Key Lifecycle Manager