PT-2022-24399 · Ibm · Ibm Cloud Pak For Security

Ben Goodspeed

+8

·

Published

2022-11-11

·

Updated

2022-11-18

·

CVE-2022-38385

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 through 1.10.2.0
Description The issue is due to improper input validation, which could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions.
Recommendations For versions 1.10.0.0 through 1.10.2.0, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-38385

Affected Products

Ibm Cloud Pak For Security