CVE-2023-38271: IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obtain sensitive information from log files.
Other sources
IBM Cloud Pak System could allow an authenticated user to obtain sensitive information from log files.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38271?
The severity of CVE-2023-38271 is considered high due to the potential for an authenticated user to access sensitive information from log files.
How do I fix CVE-2023-38271?
To fix CVE-2023-38271, update your IBM Cloud Pak System to version 2.3.3.8 or later which addresses this vulnerability.
Who is affected by CVE-2023-38271?
CVE-2023-38271 affects users of IBM Cloud Pak System versions 2.3.3.0 to 2.3.3.7, including their respective iFixes.
What kind of information can be exposed by CVE-2023-38271?
CVE-2023-38271 allows an authenticated user to obtain sensitive information from log files, potentially compromising data security.
Is CVE-2023-38271 a remote or local vulnerability?
CVE-2023-38271 is classified as a local vulnerability since it requires authentication to exploit.