CVE-2023-26270: IBM Security Guardium Data Encryption code execution
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 248119.
Other sources
IBM Security Guardium Data Encryption could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26270?
CVE-2023-26270 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2023-26270?
To address CVE-2023-26270, upgrade IBM Guardium Cloud Key Manager to version 1.10.4 or later.
What types of systems are affected by CVE-2023-26270?
CVE-2023-26270 affects IBM Guardium Cloud Key Manager versions 1.10.3 and prior.
Can CVE-2023-26270 be exploited remotely?
Yes, CVE-2023-26270 can be exploited by remote attackers through specially crafted requests.
What kind of attack does CVE-2023-26270 enable?
CVE-2023-26270 enables remote attackers to execute arbitrary code on the affected systems.