IBM Security Key Lifecycle Manager 4.1

CPE Details

IBM Security Key Lifecycle Manager 4.1
4.1
2023-12-29
09h45 +00:00
2023-12-29
09h45 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

security_key_lifecycle_manager

Version

4.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-25684 2023-03-21 16h13 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597.
9.8
Critical
CVE-2023-25686 2023-03-21 15h55 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.
6.2
Medium
CVE-2023-25923 2023-03-21 15h07 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
7.5
High
CVE-2023-25688 2023-03-21 15h01 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606.
5.3
Medium
CVE-2023-25687 2023-03-21 14h57 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
4.3
Medium
CVE-2023-25924 2023-03-21 14h53 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
8.8
High
CVE-2023-25689 2023-03-21 14h49 +00:00 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618.
5.3
Medium