CVE-2023-25923: IBM Security Key Lifecycle Manager
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
Affected products
- IBM Security Key Lifecycle Manager: version 3.0 only; version 3.0.1 only; version 4.0 only; version 4.1 only; version 4.1.1 only
Published 2023-03-21. Last modified 2026-06-17.