6.5

CVE-2023-37405

IBM Cloud Pak System information disclosure

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmCloud Pak System Version2.3.1.1
IbmCloud Pak System Version2.3.3.0 Update-
IbmCloud Pak System Version2.3.3.3 Update-
IbmCloud Pak System Version2.3.3.3 Updateifix1
IbmCloud Pak System Version2.3.3.4 Update-
IbmCloud Pak System Version2.3.3.5 Update-
IbmCloud Pak System Version2.3.3.6 Update-
IbmCloud Pak System Version2.3.3.6 Updateifix1
IbmCloud Pak System Version2.3.3.6 Updateifix2
IbmCloud Pak System Version2.3.3.7 Update-
IbmCloud Pak System Version2.3.3.7 Updateifix1
IbmCloud Pak System Version2.3.4.0 Update-
IbmCloud Pak System Version2.3.4.1 Update-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.211
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.