CVE-2023-38272
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-300
- Published
- 2025-03-27
- Last modified
- 2026-03-13
Affected products
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
- IBM Cloud Pak System
Weakness type
Related vulnerabilities
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of...
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-12991 — Multiple vulnerabilities in Ghost Robotics' Vision 60
- CVE-2025-40770 — A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions)....
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2024-50568 — A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0...
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2024-50565 — A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...