IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization.  IBM X-Force ID:  247630.
                
            References
                    | Link | Resource | 
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/247630 | VDB Entry Vendor Advisory | 
| https://www.ibm.com/support/pages/node/6962729 | Patch Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/247630 | VDB Entry Vendor Advisory | 
| https://www.ibm.com/support/pages/node/6962729 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:50
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/247630 - VDB Entry, Vendor Advisory | |
| References | () https://www.ibm.com/support/pages/node/6962729 - Patch, Vendor Advisory | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.4 | 
07 Nov 2023, 04:09
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630. | 
24 Mar 2023, 20:14
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Ibm Ibm security Key Lifecycle Manager | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.8 | 
| CPE | cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_key_lifecycle_manager:4.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1:*:*:*:*:*:*:* | |
| References | (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/247630 - VDB Entry, Vendor Advisory | |
| References | (MISC) https://www.ibm.com/support/pages/node/6962729 - Patch, Vendor Advisory | 
Information
                Published : 2023-03-22 06:15
Updated : 2024-11-21 07:50
NVD link : CVE-2023-25924
Mitre link : CVE-2023-25924
CVE.ORG link : CVE-2023-25924
JSON object : View
Products Affected
                ibm
- security_key_lifecycle_manager
CWE
                
                    
                        
                        CWE-863
                        
            Incorrect Authorization
