Skip to main content

Vendor/product archive

ibm / cloud_pak_system CVEs

Beta · best-effort

36 CVEs tagged to ibm / cloud_pak_system1 Critical, 5 High, 27 Medium, 3 Low, 0 Unrated.

CVE-2023-38005

Published Feb 17, 2026

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38265

Published Feb 17, 2026

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks ag…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2895

Published Jun 30, 2025

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject malicious H…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38007

Published Jun 27, 2025

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to HTML injectio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38272

Published Mar 27, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user wit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38716

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further atta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38714

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information abou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38713

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information abou…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38271

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38013

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in H…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38012

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker co…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38273

Published Feb 2, 2024

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4914

Published May 5, 2023

IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20479

Published May 9, 2022

IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20478

Published Jul 20, 2021

IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4928

Published Jan 4, 2021

IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execut…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4919

Published Jan 4, 2021

IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4918

Published Jan 4, 2021

IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4917

Published Jan 4, 2021

IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4916

Published Jan 4, 2021

IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4913

Published Jan 4, 2021

IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2