IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/247620 | VDB Entry |
https://www.ibm.com/support/pages/node/6964516 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/247620 | VDB Entry |
https://www.ibm.com/support/pages/node/6964516 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
13 Dec 2024, 20:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
First Time |
Ibm
Linux Microsoft Microsoft windows Linux linux Kernel Ibm aix Ibm security Guardium Key Lifecycle Manager |
|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/247620 - VDB Entry | |
References | () https://www.ibm.com/support/pages/node/6964516 - Patch, Vendor Advisory |
21 Nov 2024, 07:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/247620 - | |
References | () https://www.ibm.com/support/pages/node/6964516 - |
29 Feb 2024, 01:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-29 01:38
Updated : 2024-12-13 20:53
NVD link : CVE-2023-25921
Mitre link : CVE-2023-25921
CVE.ORG link : CVE-2023-25921
JSON object : View
Products Affected
microsoft
- windows
ibm
- security_guardium_key_lifecycle_manager
- aix
linux
- linux_kernel
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type