CVE-2023-38714
- EPSS 0.11%
- Veröffentlicht 25.01.2025 14:15:28
- Zuletzt bearbeitet 13.08.2025 17:54:10
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system.
CVE-2023-38013
- EPSS 0.11%
- Veröffentlicht 25.01.2025 14:15:27
- Zuletzt bearbeitet 13.08.2025 18:01:11
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that could aid in further attacks against the system.
CVE-2023-38012
- EPSS 0.1%
- Veröffentlicht 25.01.2025 14:15:27
- Zuletzt bearbeitet 14.08.2025 01:56:24
IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences...
CVE-2023-38273
- EPSS 0.05%
- Veröffentlicht 02.02.2024 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:13
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
CVE-2020-4914
- EPSS 0.01%
- Veröffentlicht 05.05.2023 19:15:15
- Zuletzt bearbeitet 29.01.2025 17:15:11
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.
CVE-2021-20479
- EPSS 0.1%
- Veröffentlicht 09.05.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:38
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.
CVE-2021-20478
- EPSS 0.04%
- Veröffentlicht 20.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:38
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.
CVE-2020-4928
- EPSS 0.07%
- Veröffentlicht 04.01.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:26
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.
CVE-2020-4919
- EPSS 0.14%
- Veröffentlicht 04.01.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:25
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.
CVE-2020-4918
- EPSS 0.04%
- Veröffentlicht 04.01.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:25
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.