First published: Tue Apr 25 2023(Updated: )
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to execute arbitrary code on the system, caused by an angular template injection flaw. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 248119.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Cloud Key Manager | <=1.10.3 | |
<=1.10.3 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26270 is classified as a critical vulnerability due to its potential to allow remote code execution.
To address CVE-2023-26270, upgrade IBM Guardium Cloud Key Manager to version 1.10.4 or later.
CVE-2023-26270 affects IBM Guardium Cloud Key Manager versions 1.10.3 and prior.
Yes, CVE-2023-26270 can be exploited by remote attackers through specially crafted requests.
CVE-2023-26270 enables remote attackers to execute arbitrary code on the affected systems.