CVE-2023-25925

Severity
8.8HIGH
EPSS
0.4%
top 39.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateFeb 29

Description

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages2 packages

CVEListV5ibm/security_guardium_key_lifecycle_manager3.0, 3.0.1, 4.0, 4.1, 4.1.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h9v6-x8w6-frrm: IBM Security Guardium Key Lifecycle Manager 32024-02-29
CVEList
IBM Security Guardium Key Lifecycle Manager command injection2024-02-28
CVE-2023-25925 (HIGH CVSS 8.8) | IBM Security Guardium Key Lifecycle | cvebase.io