cbcvebase.

Ibm Cloud Pak System vulnerabilities

36 known vulnerabilities affecting ibm/cloud_pak_system.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM21LOW3

Vulnerabilities

Page 2 of 2
CVE-2025-2895P4MEDIUMCVSS 5.4v2.3.3.6v2.3.3.7+5 more2025-06-30
CVE-2025-2895 [MEDIUM] CWE-80 CVE-2025-2895: IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iF IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
nvd
CVE-2019-4098P4MEDIUMCVSS 5.4v2.3v2.3.0.12019-12-03
CVE-2019-4098 [MEDIUM] CWE-79 CVE-2019-4098: IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allow IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158020.
nvd
CVE-2019-4468P4MEDIUMCVSS 5.4v2.3v2.3.0.1+1 more2019-12-03
CVE-2019-4468 [MEDIUM] CWE-79 CVE-2019-4468: IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allow IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163777.
nvd
CVE-2019-4226P4MEDIUMCVSS 5.4v2.3v2.3.0.1+1 more2019-12-03
CVE-2019-4226 [MEDIUM] CWE-79 CVE-2019-4226: IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allow IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159243.
nvd
CVE-2019-4467P4MEDIUMCVSS 5.4v2.3v2.3.0.1+1 more2019-12-03
CVE-2019-4467 [MEDIUM] CWE-79 CVE-2019-4467: IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allow IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163776.
nvd
CVE-2023-38005P4MEDIUMCVSS 4.3v2.3.3.6v2.3.3.7+4 more2026-02-17
CVE-2023-38005 [MEDIUM] CWE-284 CVE-2023-38005: IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated us IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.
nvd
CVE-2020-4914P4MEDIUMCVSS 5.5≥ 2.3.3.0, < 2.3.3.62023-05-05
CVE-2020-4914 [MEDIUM] CWE-613 CVE-2020-4914: IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which co IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.
nvd
CVE-2020-4916P4MEDIUMCVSS 4.8≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4916 [MEDIUM] CWE-79 CVE-2020-4916: IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to e IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191390.
nvd
CVE-2020-4910P4MEDIUMCVSS 4.8≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4910 [MEDIUM] CWE-79 CVE-2020-4910: IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to e IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191274.
nvd
CVE-2020-4909P4MEDIUMCVSS 4.8≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4909 [MEDIUM] CWE-79 CVE-2020-4909: IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to e IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191273.
nvd
CVE-2019-4095P4MEDIUMCVSS 4.3v2.3v2.3.0.12019-12-10
CVE-2019-4095 [MEDIUM] CWE-352 CVE-2019-4095: IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker t IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.
nvd
CVE-2020-4913P4MEDIUMCVSS 4.4≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4913 [MEDIUM] CWE-200 CVE-2020-4913: IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privile IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
nvd
CVE-2020-4918P4MEDIUMCVSS 4.4≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4918 [MEDIUM] CWE-639 CVE-2020-4918: IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due t IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.
nvd
CVE-2020-4919P4LOWCVSS 3.8≥ 2.3.0.0, < 2.3.3.3v2.32021-01-04
CVE-2020-4919 [LOW] CVE-2020-4919: IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privile IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.
nvd
CVE-2019-4465P4LOWCVSS 3.3v2.3v2.3.0.1+1 more2019-12-03
CVE-2019-4465 [LOW] CWE-269 CVE-2019-4465: IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by anot IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.
nvd
CVE-2021-20478P4LOWCVSS 3.3v2.32021-07-20
CVE-2021-20478 [LOW] CVE-2021-20478: IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of anothe IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.
nvd
Ibm Cloud Pak System vulnerabilities | cvebase