CVE-2023-25921: IBM Security Guardium Key Lifecycle Manager file upload
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
Other sources
IBM Security Guardium Key Lifecycle Manager allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25921?
CVE-2023-25921 has been rated as a high-severity vulnerability due to the potential for file uploads of dangerous types.
How do I fix CVE-2023-25921?
To fix CVE-2023-25921, apply the patch available for IBM Security Guardium Key Lifecycle Manager version up to 4.1.1.6.
Which versions of IBM products are affected by CVE-2023-25921?
CVE-2023-25921 affects IBM Security Guardium Key Lifecycle Manager versions 3.0 to 4.1.1.1.
What type of attacks can exploit CVE-2023-25921?
CVE-2023-25921 can be exploited by allowing attackers to upload or transfer files of dangerous types for automated processing.
Is there a workaround for CVE-2023-25921 if I cannot apply the patch immediately?
Currently, there are no documented workarounds for CVE-2023-25921, so it is essential to apply the patch as soon as possible.