CVE-2023-38013: IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that could aid in further attacks against the system.
Other sources
IBM Cloud Pak System could disclose sensitive information in HTTP responses that could aid in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38013?
CVE-2023-38013 is classified as a critical vulnerability due to its potential to disclose sensitive information and facilitate further attacks.
How do I fix CVE-2023-38013?
To fix CVE-2023-38013, upgrade IBM Cloud Pak System to version 2.3.3.8 or later, which addresses the vulnerability.
What versions of IBM Cloud Pak System are affected by CVE-2023-38013?
CVE-2023-38013 affects IBM Cloud Pak System versions from 2.3.3.0 to 2.3.3.7, including iFix versions.
What type of information does CVE-2023-38013 disclose?
CVE-2023-38013 may disclose sensitive information in HTTP responses, which can lead to further exploitation.
Is there a workaround for CVE-2023-38013?
There are no officially documented workarounds for CVE-2023-38013, so upgrading the system is the recommended action.