CVE-2023-25924

EUVD-2023-29812
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization.  IBM X-Force ID:  247630.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
ibmCNA
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_key_lifecycle_manager
3.0
ibmsecurity_key_lifecycle_manager
3.0.1
ibmsecurity_key_lifecycle_manager
4.0
ibmsecurity_key_lifecycle_manager
4.1
ibmsecurity_key_lifecycle_manager
4.1.1
𝑥
= Vulnerable software versions