6.5
CVE-2023-37405
- EPSS 0.02%
- Published 27.03.2025 17:20:04
- Last modified 18.08.2025 18:46:32
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak System Version2.3.1.1
Ibm ≫ Cloud Pak System Version2.3.3.0 Update-
Ibm ≫ Cloud Pak System Version2.3.3.3 Update-
Ibm ≫ Cloud Pak System Version2.3.3.3 Updateifix1
Ibm ≫ Cloud Pak System Version2.3.3.4 Update-
Ibm ≫ Cloud Pak System Version2.3.3.5 Update-
Ibm ≫ Cloud Pak System Version2.3.3.6 Update-
Ibm ≫ Cloud Pak System Version2.3.3.6 Updateifix1
Ibm ≫ Cloud Pak System Version2.3.3.6 Updateifix2
Ibm ≫ Cloud Pak System Version2.3.3.7 Update-
Ibm ≫ Cloud Pak System Version2.3.3.7 Updateifix1
Ibm ≫ Cloud Pak System Version2.3.4.0 Update-
Ibm ≫ Cloud Pak System Version2.3.4.1 Update-
Ibm ≫ Cloud Pak System Software Suite Version2.3.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.032 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@us.ibm.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.