CVE-2023-38272
MEDIUMDescription
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.
Is your site exposed to CVE-2023-38272?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
| ibm | cloud_pak_system |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-38272? +
How severe is CVE-2023-38272? +
What products are affected by CVE-2023-38272? +
How do I check if I'm vulnerable to CVE-2023-38272? +
Related Vulnerabilities
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK …
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package …
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, …
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …
dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party …
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker …