CVE-2023-25687

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_key_lifecycle_manager:4.1.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:49

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/247602 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/247602 - VDB Entry
References () https://www.ibm.com/support/pages/node/6962729 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/6962729 - Patch, Vendor Advisory

07 Nov 2023, 04:09

Type Values Removed Values Added
Summary IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602. IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.

Information

Published : 2023-03-21 15:15

Updated : 2024-11-21 07:49


NVD link : CVE-2023-25687

Mitre link : CVE-2023-25687

CVE.ORG link : CVE-2023-25687


JSON object : View

Products Affected

ibm

  • security_key_lifecycle_manager
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-532

Insertion of Sensitive Information into Log File