CVE-2023-38265

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7259955 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*

History

23 Feb 2026, 13:10

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7259955 - () https://www.ibm.com/support/pages/node/7259955 - Vendor Advisory
First Time Ibm cloud Pak System
Ibm

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1 y 2.3.5.0 podría divulgar información de ubicación de carpetas a un atacante no autenticado que podría facilitar ataques posteriores contra el sistema.

17 Feb 2026, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 20:22

Updated : 2026-02-23 13:10


NVD link : CVE-2023-38265

Mitre link : CVE-2023-38265

CVE.ORG link : CVE-2023-38265


JSON object : View

Products Affected

ibm

  • cloud_pak_system
CWE
CWE-548

Exposure of Information Through Directory Listing