exchange.xforce.ibmcloud.comvdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/247602 CVE-2023-25687
MEDIUM
IBM Security Key Lifecycle Manager information disclosure
Record summary
CVE-2023-25687 has a selected CVSS score of 4.3 (medium).
Description
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Security Key Lifecycle ManagerBrowse IBM / Security Key Lifecycle ManagerDefault status: unaffected | CVE List | 3.0, 3.0.1, 4.0, 4.1, 4.1.1 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-25687 ibm.comVendor advisory
https://www.ibm.com/support/pages/node/6962729