CVE-2023-37405: IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.
Other sources
IBM Cloud Pak System stores sensitive data in memory, that could be obtained by an unauthorized user.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37405?
CVE-2023-37405 has been rated as a significant vulnerability due to its potential exposure of sensitive data in memory.
How do I fix CVE-2023-37405?
To address CVE-2023-37405, update IBM Cloud Pak System to the latest version or apply the recommended security patches.
What versions of IBM Cloud Pak System are affected by CVE-2023-37405?
CVE-2023-37405 affects IBM Cloud Pak System versions 2.3.1.1 to 2.3.4.1, including specific iFix versions.
Can CVE-2023-37405 be exploited by an unauthorized user?
Yes, CVE-2023-37405 can be exploited by an unauthorized user to access sensitive data stored in memory.
What type of data is at risk with CVE-2023-37405?
CVE-2023-37405 exposes sensitive data that is stored in memory, which could include personal or proprietary information.