CVE-2023-38714: IBM Cloud Pak System information disclosure
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about the system that could aid in further attacks against the system.
Other sources
IBM Cloud Pak System could disclose sensitive information about the system that could aid in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38714?
CVE-2023-38714 is considered a high severity vulnerability due to potential sensitive information disclosure.
How do I fix CVE-2023-38714?
To fix CVE-2023-38714, upgrade your IBM Cloud Pak System to a secure version above 2.3.3.7 iFix1.
What are the affected versions of CVE-2023-38714?
CVE-2023-38714 affects IBM Cloud Pak System versions 2.3.3.0 through 2.3.3.7 iFix1.
What kind of information may be disclosed by CVE-2023-38714?
CVE-2023-38714 may disclose sensitive system information that could be exploited for further attacks.
Is CVE-2023-38714 reversible after applying the fix?
Once CVE-2023-38714 is patched by upgrading, the vulnerabilities associated with it are resolved and non-reversible.