CVE-2023-25685: Medium severity ibm security guardium key lifecycle manager vulnerability
IBM Security Guardium Key Lifecycle Manager is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25685?
CVE-2023-25685 has a high severity due to its potential for an XML External Entity Injection attack.
How do I fix CVE-2023-25685?
To fix CVE-2023-25685, update to an IBM Security Guardium Key Lifecycle Manager version that includes the necessary patches.
What types of attacks can exploit CVE-2023-25685?
CVE-2023-25685 can be exploited through XML External Entity Injection, allowing attackers to expose sensitive information.
Which versions of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-25685?
IBM Security Guardium Key Lifecycle Manager versions up to and including 4.1.1 are affected by CVE-2023-25685.
Can CVE-2023-25685 lead to a denial of service?
Yes, CVE-2023-25685 can potentially lead to a denial of service by consuming excessive memory resources.