Lucene search

K
nvd[email protected]NVD:CVE-2023-25922
HistoryFeb 28, 2024 - 10:15 p.m.

CVE-2023-25922

2024-02-2822:15:25
CWE-434
web.nvd.nist.gov
1
ibm security guardium
file upload
dangerous types
product environment
x-force id
cve-2023-25922

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.9

Confidence

High

EPSS

0

Percentile

9.0%

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment. IBM X-Force ID: 247621.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

4.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-25922