CVE-2023-38271
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-38271 affects multiple versions of IBM Cloud Pak System, including 2.3.3.0, 2.3.3.3, iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, iFix1, and iFix2, as well as 2.3.3.7 and 2.3.3.7 iFix1. This vulnerability grants authenticated users the ability to access sensitive information from log files, potentially leading to data breaches or unauthorized access. IBM strongly recommends users update their systems to the latest version as soon as possible to mitigate this risk. The exact method of exploitation is currently unclear, but the vulnerability poses a significant threat to system security and confidentiality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation