CVE-2023-25923: IBM Security Key Lifecycle Manager denial of service
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
Other sources
IBM Security Guardium Key Lifecycle Manager could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-25923?
CVE-2023-25923 is a vulnerability in IBM Security Guardium Key Lifecycle Manager that could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization.
What is the severity level of CVE-2023-25923?
CVE-2023-25923 has a severity level of high, with a severity value of 7.5.
Which software versions are affected by CVE-2023-25923?
IBM Security Guardium Key Lifecycle Manager versions 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 are affected by CVE-2023-25923.
How can an attacker exploit CVE-2023-25923?
An attacker can exploit CVE-2023-25923 by uploading files that can be used in a denial of service attack.
Is there a fix available for CVE-2023-25923?
Yes, IBM has provided a fix for CVE-2023-25923. Please refer to the vendor's website or support pages for more information.