CVE-2023-26271: IBM Security Guardium Data Encryption information disclosure
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.
Other sources
IBM Security Guardium Data Encryption uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26271?
The severity of CVE-2023-26271 is classified as high due to its potential for exploitation through brute force attacks.
How do I fix CVE-2023-26271?
To fix CVE-2023-26271, implement stronger account lockout policies and update to a version of IBM Guardium Cloud Key Manager that addresses this vulnerability.
What software versions are affected by CVE-2023-26271?
IBM Guardium Cloud Key Manager versions up to and including 1.10.3 are affected by CVE-2023-26271.
Can CVE-2023-26271 lead to unauthorized access?
Yes, CVE-2023-26271 can lead to unauthorized access if an attacker successfully brute forces account credentials.
Is there a workaround for CVE-2023-26271?
While a permanent fix is recommended, temporarily enhancing account lockout policies may serve as a workaround for CVE-2023-26271 until a patch is applied.