CVE-2023-25924: IBM Security Key Lifecycle Manager

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.

Affected products

  • IBM Security Key Lifecycle Manager: version 3.0 only; version 3.0.1 only; version 4.0 only; version 4.1 only; version 4.1.1 only

Published 2023-03-22. Last modified 2026-06-17.