CVE-2023-26272: IBM Security Guardium Data Encryption information disclosure
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 248133.
Other sources
IBM Security Guardium Data Encryption could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26272?
The severity of CVE-2023-26272 is considered to be high due to its ability to expose sensitive information.
How do I fix CVE-2023-26272?
To fix CVE-2023-26272, upgrade IBM Guardium Cloud Key Manager to version 1.10.4 or later.
What type of information is vulnerable in CVE-2023-26272?
CVE-2023-26272 allows a remote attacker to obtain sensitive information from detailed technical error messages.
Who is affected by CVE-2023-26272?
CVE-2023-26272 affects users of IBM Guardium Cloud Key Manager version 1.10.3 and lower.
Is there a workaround for CVE-2023-26272?
Currently, there is no specific workaround for CVE-2023-26272 other than updating to the latest version.