CVE-2023-47702

IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 4.3
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/271196 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/271196 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7091157 - Vendor Advisory () https://www.ibm.com/support/pages/node/7091157 - Vendor Advisory

22 Dec 2023, 10:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:ibm:security_guardium_key_lifecycle_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Summary
  • (es) IBM Security Guardium Key Lifecycle Manager 4.3 podría permitir que un atacante remoto atraviese directorios del sistema. Un atacante podría enviar una solicitud URL especialmente manipulada que contenga secuencias de "puntos" (/../) para ver los archivos modificados en el sistema. ID de IBM X-Force: 271196.
First Time Linux linux Kernel
Ibm aix
Microsoft windows
Linux
Ibm security Guardium Key Lifecycle Manager
Ibm
Microsoft
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/271196 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/271196 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7091157 - () https://www.ibm.com/support/pages/node/7091157 - Vendor Advisory

20 Dec 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-20 02:15

Updated : 2024-11-21 08:30


NVD link : CVE-2023-47702

Mitre link : CVE-2023-47702

CVE.ORG link : CVE-2023-47702


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • security_guardium_key_lifecycle_manager
  • aix

microsoft

  • windows
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')