CVE-2023-25924
Published Mar 22, 2023
Last updated a year ago
Overview
- Description
- IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- psirt@us.ibm.com
- CWE-863
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5744D219-B3BD-4CBA-888E-2920B5A7FD99" }, { "criteria": "cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC8182ED-77F8-4931-88ED-385163DD4091" }, { "criteria": "cpe:2.3:a:ibm:security_key_lifecycle_manager:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D815B49-CE8E-45C8-A025-509253F5252C" }, { "criteria": "cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D098B3CA-E84B-42CE-ABF5-97D80864C553" }, { "criteria": "cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09C04E4B-EAA5-43E8-A6F3-251ED2D6C1E8" } ], "operator": "OR" } ] } ]