PT-2024-13336 · Ibm · Ibm Cloud Pak For Multicloud Management

Published

2024-09-26

·

Updated

2025-08-08

·

CVE-2023-46175

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Cloud Pak for Multicloud Management versions 2.3 through 2.3 FP8
Description The issue concerns the storage of user credentials in log files in plain clear text, which can be accessed by a privileged user. This results in the exposure of sensitive information via log files.
Recommendations For IBM Cloud Pak for Multicloud Management versions 2.3 through 2.3 FP8, upgrade the affected component immediately to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2023-46175

Affected Products

Ibm Cloud Pak For Multicloud Management