7.5
CVE-2023-25923
- EPSS 0.35%
- Veröffentlicht 21.03.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 07:50:25
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Security Key Lifecycle Manager denial of service
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Key Lifecycle Manager Version3.0
Ibm ≫ Security Key Lifecycle Manager Version3.0.1
Ibm ≫ Security Key Lifecycle Manager Version4.0
Ibm ≫ Security Key Lifecycle Manager Version4.1
Ibm ≫ Security Key Lifecycle Manager Version4.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.574 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| psirt@us.ibm.com | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.