CVE-2023-25925: IBM Security Guardium Key Lifecycle Manager

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.

Affected products

  • IBM Security Guardium Key Lifecycle Manager: from 3.0.0, before 4.1.1.7 (fixed in 4.1.1.7)

Published 2024-02-28. Last modified 2026-06-17.