First published: Thu Mar 09 2023(Updated: )
IBM Security Guardium Key Lifecycle Manager is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Security Key Lifecycle Manager | <=3.0 | |
Ibm Security Key Lifecycle Manager | <=3.0.1 | |
IBM Security Guardium Key Lifecycle Manager | <=4.0 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1 | |
IBM Security Guardium Key Lifecycle Manager | <=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25685 has a high severity due to its potential for an XML External Entity Injection attack.
To fix CVE-2023-25685, update to an IBM Security Guardium Key Lifecycle Manager version that includes the necessary patches.
CVE-2023-25685 can be exploited through XML External Entity Injection, allowing attackers to expose sensitive information.
IBM Security Guardium Key Lifecycle Manager versions up to and including 4.1.1 are affected by CVE-2023-25685.
Yes, CVE-2023-25685 can potentially lead to a denial of service by consuming excessive memory resources.