CVE-2023-25926: IBM Security Guardium Key Lifecycle Manager XML external entity injection
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 247599.
Other sources
IBM Security Guardium Key Lifecycle Manager could allow a local privileged user to escalate their privileges to a higher level of access.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25926?
The severity of CVE-2023-25926 is significant due to its potential for XML External Entity Injection, allowing attackers to expose sensitive information.
How do I fix CVE-2023-25926?
To fix CVE-2023-25926, update to the latest patched version of IBM Security Guardium Key Lifecycle Manager.
Which versions of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-25926?
Versions 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-25926.
What kind of attack does CVE-2023-25926 enable?
CVE-2023-25926 enables XML External Entity Injection attacks, which can lead to the disclosure of sensitive data.
Can a remote attacker exploit CVE-2023-25926?
Yes, a remote attacker can exploit CVE-2023-25926 to expose sensitive information or consume memory resources.