PT-2023-20362 · Ibm · Ibm Security Guardium Key Lifecycle Manager

·

CVE-2023-25923

·

Published

2023-03-21

·

Updated

2023-03-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Guardium Key Lifecycle Manager versions 3.0 through 4.1.1
Description The issue allows an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
Recommendations For versions 3.0 through 4.1.1, consider restricting file upload capabilities to authorized users as a temporary workaround until a patch is available.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-25923

Affected Products

Ibm Security Guardium Key Lifecycle Manager