CVE-2023-38271

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 25, 2025
CWE ID 532

Summary

CVE-2023-38271 affects multiple versions of IBM Cloud Pak System, including 2.3.3.0, 2.3.3.3, iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, iFix1, and iFix2, as well as 2.3.3.7 and 2.3.3.7 iFix1. This vulnerability grants authenticated users the ability to access sensitive information from log files, potentially leading to data breaches or unauthorized access. IBM strongly recommends users update their systems to the latest version as soon as possible to mitigate this risk. The exact method of exploitation is currently unclear, but the vulnerability poses a significant threat to system security and confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share