CVE-2023-37405

CWE-3113 documents3 sources
Severity
6.5MEDIUM
EPSS
0.1%
top 70.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27

Description

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5ibm/cloud_pak_system11 versions+10
NVDibm/cloud_pak_system9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-56r2-5qqm-ppfv: IBM Cloud Pak System 22025-03-27
CVEList
IBM Cloud Pak System information disclosure2025-03-27
CVE-2023-37405 (MEDIUM CVSS 6.5) | IBM Cloud Pak System 2.3.3.0 | cvebase.io