PT-2023-20362 · Ibm · Ibm Security Guardium Key Lifecycle Manager

·

CVE-2023-25923

·

Publicado

2023-03-21

·

Atualizado

2023-03-24

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Guardium Key Lifecycle Manager versions 3.0 through 4.1.1
Description The issue allows an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
Recommendations For versions 3.0 through 4.1.1, consider restricting file upload capabilities to authorized users as a temporary workaround until a patch is available.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25923

Produtos afetados

Ibm Security Guardium Key Lifecycle Manager