CVE-2023-38272
MEDIUMDescription
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.
Is your site exposed to CVE-2023-38272?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-38272? +
How severe is CVE-2023-38272? +
What products are affected by CVE-2023-38272? +
How do I check if I'm vulnerable to CVE-2023-38272? +
Related Vulnerabilities
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK …
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party …
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker …
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker …