CVE-2023-38265

I

BM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

References
Link Resource
https://www.ibm.com/support/pages/node/7259955 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*

History

23 Feb 2026, 13:10

Type Values Removed Values Added
First Time Ibm
Ibm cloud Pak System
References () https://www.ibm.com/support/pages/node/7259955 - () https://www.ibm.com/support/pages/node/7259955 - Vendor Advisory
CPE cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1 y 2.3.5.0 podría divulgar información de ubicación de carpetas a un atacante no autenticado que podría facilitar ataques posteriores contra el sistema.

17 Feb 2026, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 20:22

Updated : 2026-02-23 13:10


NVD link : CVE-2023-38265

Mitre link : CVE-2023-38265

CVE.ORG link : CVE-2023-38265


JSON object : View

Products Affected
CWE
CWE-548

Exposure of Information Through Directory Listing