CVE-2023-38272

CWE-3003 documents3 sources
Severity
7.5HIGH
EPSS
0.2%
top 61.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27

Description

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/cloud_pak_system12 versions+11
NVDibm/cloud_pak_system9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-w7fp-pj56-6xc6: IBM Cloud Pak System 22025-03-27
CVEList
IBM Cloud Pak System information disclosure2025-03-27
CVE-2023-38272 (HIGH CVSS 7.5) | IBM Cloud Pak System 2.3.3.0 | cvebase.io