CVE-2022-38385

HIGH

IBM Cloud Pak for Security <1.10.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/6833586

Scores

CVSS v3 7.1
EPSS 0.0033
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
ibm/cloud_pak_for_security 1.10.0.0 - 1.10.2.0
Published Nov 15, 2022
Tracked Since Feb 18, 2026