CVE-2022-38385: Input Validation
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.
Other sources
IBM Cloud Pak for Security (CP4S) could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-38385?
CVE-2022-38385 is a vulnerability in IBM Cloud Pak for Security (CP4S) that could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation.
How does CVE-2022-38385 affect IBM Cloud Pak for Security (CP4S)?
CVE-2022-38385 affects IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.2.0, allowing an authenticated user to obtain highly sensitive information or perform unauthorized actions.
What is the severity of CVE-2022-38385?
The severity of CVE-2022-38385 is rated as high, with a severity value of 8.1.
How can I fix CVE-2022-38385?
To fix CVE-2022-38385, users of IBM Cloud Pak for Security (CP4S) should upgrade to a version higher than 1.10.2.0, as this vulnerability was patched in later releases.
Where can I find more information about CVE-2022-38385?
You can find more information about CVE-2022-38385 on the IBM X-Force Exchange website at https://exchange.xforce.ibmcloud.com/vulnerabilities/233777 or on the IBM support page at https://www.ibm.com/support/pages/node/6833586.