Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41839 | IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7148474 |
|
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:* |
Mon, 27 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 25 Jan 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Title | IBM Cloud Pak System directory traversal | |
| First Time appeared |
Ibm
Ibm cloud Pak System |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:ifix1:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:ifix2:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:*:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:ifix1:*:*:*:*:*:* cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm cloud Pak System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-27T17:03:37.389Z
Reserved: 2023-07-11T17:33:12.812Z
Link: CVE-2023-38012
Updated: 2025-01-27T17:03:31.998Z
Status : Analyzed
Published: 2025-01-25T14:15:27.337
Modified: 2025-08-14T01:56:24.343
Link: CVE-2023-38012
No data.
OpenCVE Enrichment
No data.
EUVD