First published: Tue Apr 25 2023(Updated: )
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Cloud Key Manager | <=1.10.3 | |
<=1.10.3 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-26271 is classified as high due to its potential for exploitation through brute force attacks.
To fix CVE-2023-26271, implement stronger account lockout policies and update to a version of IBM Guardium Cloud Key Manager that addresses this vulnerability.
IBM Guardium Cloud Key Manager versions up to and including 1.10.3 are affected by CVE-2023-26271.
Yes, CVE-2023-26271 can lead to unauthorized access if an attacker successfully brute forces account credentials.
While a permanent fix is recommended, temporarily enhancing account lockout policies may serve as a workaround for CVE-2023-26271 until a patch is applied.