IBM Cloud Pak System Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in IBM Cloud Pak System versions 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1. This vulnerability could lead to the unintentional disclosure of sensitive system information, which might be exploited to conduct further attacks against the system.

Impact

Successful exploitation of this vulnerability could provide an attacker with sensitive information that could be used to compromise the system or its data.

Remediation

Users of IBM Cloud Pak System on Intel should upgrade to version 2.3.4.0. For those on Power, version 2.3.5.0 is recommended. Instructions for upgrading are available on the IBM Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.