CVE-2023-47707: IBM Security Guardium Key Lifecycle Manager cross-site scripting
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
Other sources
IBM Security Guardium Key Lifecycle Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47707?
CVE-2023-47707 is classified as a medium severity vulnerability.
How do I fix CVE-2023-47707?
To fix CVE-2023-47707, you should apply the latest patches provided by IBM for the Security Guardium Key Lifecycle Manager.
What types of attacks can CVE-2023-47707 facilitate?
CVE-2023-47707 can facilitate cross-site scripting attacks, allowing the execution of arbitrary JavaScript code in the Web UI.
What impact does CVE-2023-47707 have on user credentials?
CVE-2023-47707 can potentially lead to the disclosure of user credentials within a trusted session.
Which versions of IBM Security Guardium Key Lifecycle Manager are affected by CVE-2023-47707?
CVE-2023-47707 affects IBM Security Guardium Key Lifecycle Manager versions up to and including 4.2.0.2.