CVE-2023-25686: IBM Security Key Lifecycle Manager

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.

Affected products

  • IBM Security Key Lifecycle Manager: version 3.0 only; version 3.0.1 only; version 4.0 only; version 4.1 only; version 4.1.1 only

Published 2023-03-21. Last modified 2026-06-17.