CVE-2026-13463: Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []

Published Jul 9, 2026
·
Updated

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

Other sources

IBM Storage Protect could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

IBM

Affected Software

4 affected components
IBM IBM Cloud Pak System=2.3.5.0
IBM Cloud Pak System<=2.3.5.0
All of the following
IBM Cloud Pak System=2.3.5.0
IBM AIX

Event History

Jul 9, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 28, 2026
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2026-13463?

CVE-2026-13463 has a severity rating of 7.5, classified as high risk.

2

What type of exposure does CVE-2026-13463 present?

CVE-2026-13463 allows a local attacker to potentially obtain sensitive information.

3

How do I fix CVE-2026-13463?

To fix CVE-2026-13463, apply the latest updates and patches provided by IBM for the affected IBM Cloud Pak System.

4

What systems are affected by CVE-2026-13463?

CVE-2026-13463 affects IBM Cloud Pak System version 2.3.5.0.

5

What is the cause of the vulnerability CVE-2026-13463?

CVE-2026-13463 is caused by the insertion of credentials into log files in IBM Storage Protect.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203