CVE-2023-47705: IBM Security Guardium Key Lifecycle Manager improper input validation
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
Other sources
IBM Security Guardium Key Lifecycle Manager could allow an authenticated user to manipulate username data due to improper input validation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47705?
CVE-2023-47705 is classified with a moderate severity level due to improper input validation allowing manipulation of username data.
How do I fix CVE-2023-47705?
To address CVE-2023-47705, apply the latest patches available for IBM Security Guardium Key Lifecycle Manager.
Which versions of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-47705?
CVE-2023-47705 affects versions up to 4.2.0 inclusive of IBM Security Guardium Key Lifecycle Manager.
Can an unauthenticated user exploit CVE-2023-47705?
No, CVE-2023-47705 requires authentication to exploit due to the nature of the vulnerability.
Is there a workaround for CVE-2023-47705 until a patch is applied?
Currently, the recommended action is to apply the patch as there are no reliable workarounds for CVE-2023-47705.