6.5
CVE-2023-38271
- EPSS 0.32%
- Veröffentlicht 25.01.2025 14:15:28
- Zuletzt bearbeitet 13.08.2025 17:59:56
- Erkennungen
IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Cloud Pak System Version 2.3.3.0 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.3 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.3 Update ifix1
Ibm ≫ Cloud Pak System Version 2.3.3.4 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.5 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.6 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.6 Update ifix1
Ibm ≫ Cloud Pak System Version 2.3.3.6 Update ifix2
Ibm ≫ Cloud Pak System Version 2.3.3.7 Update -
Ibm ≫ Cloud Pak System Version 2.3.3.7 Update ifix1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.246 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| IBM | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://www.ibm.com/support/pages/node/7159533