CVE-2023-38272: IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1
could allow a user with access to the network to obtain sensitive information from CLI arguments.
Other sources
IBM Cloud Pak System could allow a user with access to the network to obtain sensitive information from CLI arguements.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38272?
The severity of CVE-2023-38272 is classified as a medium vulnerability.
How do I fix CVE-2023-38272?
To fix CVE-2023-38272, it is recommended to upgrade to the latest version of IBM Cloud Pak System that addresses this vulnerability.
What is the impact of CVE-2023-38272?
CVE-2023-38272 allows a network user to potentially obtain sensitive information from command line interface (CLI) arguments.
Which versions of IBM Cloud Pak System are affected by CVE-2023-38272?
CVE-2023-38272 affects several versions including 2.3.3.0, 2.3.3.3, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.7, and 2.3.4.1.
What are the exploit conditions for CVE-2023-38272?
CVE-2023-38272 can be exploited by a user who has network access to the IBM Cloud Pak System.