CVE-2023-25922: IBM Security Guardium Key Lifecycle Manager file upload
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
Other sources
IBM Security Guardium Key Lifecycle Manager allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25922?
CVE-2023-25922 is considered a high severity vulnerability due to the ability for attackers to upload or transfer dangerous file types.
How do I fix CVE-2023-25922?
To fix CVE-2023-25922, apply the available patches provided by IBM for the affected versions of the Security Guardium Key Lifecycle Manager.
Which versions of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-25922?
Versions 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-25922.
What types of attacks can be conducted due to CVE-2023-25922?
CVE-2023-25922 allows attackers to upload files of dangerous types that may be processed in the product's environment, potentially leading to further exploitation.
Is there any known exploit for CVE-2023-25922?
As of now, specific details about publicly known exploits for CVE-2023-25922 have not been disclosed.