CVE-2023-47702: IBM Security Guardium Key Lifecycle Manager

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.

Affected products

  • IBM Security Guardium Key Lifecycle Manager: from 4.2.0, before 4.2.0.2 (fixed in 4.2.0.2)

Published 2023-12-20. Last modified 2026-06-17.