CVE-2023-38005: Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.
Other sources
IBM Cloud Pak System could allow an authenticated user to perform unauthorized tasks due to improper access controls.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38005?
CVE-2023-38005 has a medium severity rating due to improper access control vulnerabilities that may allow unauthorized access.
How do I fix CVE-2023-38005?
To mitigate CVE-2023-38005, update your IBM Cloud Pak System to the latest version that addresses the access control vulnerabilities.
Who is affected by CVE-2023-38005?
CVE-2023-38005 affects IBM Cloud Pak System versions 2.3.3.6 to 2.3.5.0.
What type of vulnerability is CVE-2023-38005?
CVE-2023-38005 is characterized as an improper access control and information exposure vulnerability.
Can CVE-2023-38005 be exploited by authenticated users?
Yes, CVE-2023-38005 can be exploited by authenticated users who may perform unauthorized tasks due to the access control issues.