CVE-2022-38383 MEDIUM

CVE-2022-38383: IBM Cloud Pak for Security information disclosure

Vendor Ibm
Product Cloud Pak for Security
Weakness CWE-525
Published June 28, 2024
Last update August 3, 2024

CVSS base score

4.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.

Key dates

02Disclosure timeline

June 28, 2024 CVE published
August 3, 2024 Record updated