First published: Tue Apr 25 2023(Updated: )
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 248133.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Guardium Cloud Key Manager | <=1.10.3 | |
<=1.10.3 and lower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-26272 is considered to be high due to its ability to expose sensitive information.
To fix CVE-2023-26272, upgrade IBM Guardium Cloud Key Manager to version 1.10.4 or later.
CVE-2023-26272 allows a remote attacker to obtain sensitive information from detailed technical error messages.
CVE-2023-26272 affects users of IBM Guardium Cloud Key Manager version 1.10.3 and lower.
Currently, there is no specific workaround for CVE-2023-26272 other than updating to the latest version.