8.8
CVE-2023-25922
- EPSS 0.05%
- Veröffentlicht 28.02.2024 22:15:25
- Zuletzt bearbeitet 13.12.2024 20:59:47
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247621.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Guardium Key Lifecycle Manager Version >= 3.0.0 < 4.1.1.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.162 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.