CVE-2023-25922

I

BM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

13 Dec 2024, 20:59

Type Values Removed Values Added
First Time Ibm aix
Ibm
Linux linux Kernel
Microsoft windows
Linux
Microsoft
Ibm security Guardium Key Lifecycle Manager
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/247621 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/247621 - VDB Entry
References () https://www.ibm.com/support/pages/node/6964516 - () https://www.ibm.com/support/pages/node/6964516 - Patch, Vendor Advisory

21 Nov 2024, 07:50

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/247621 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/247621 -
References () https://www.ibm.com/support/pages/node/6964516 - () https://www.ibm.com/support/pages/node/6964516 -

Information

Published : 2024-02-28 22:15

Updated : 2024-12-13 20:59


NVD link : CVE-2023-25922

Mitre link : CVE-2023-25922

CVE.ORG link : CVE-2023-25922


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type