PT-2025-27231 · Ibm · Ibm Cloud Pak System

Published

2025-06-27

·

Updated

2025-08-14

·

CVE-2023-38007

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: IBM Cloud Pak System versions 2.3.3.6 through 2.3.5.0
Description: A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. This issue is related to HTML injection.
Recommendations: For IBM Cloud Pak System versions 2.3.3.6 through 2.3.5.0, update to a version that includes the fix for this issue to prevent HTML injection attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09843
CVE-2023-38007

Affected Products

Ibm Cloud Pak System