IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HTTP responses that could aid in further attacks against the system.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloud_pak_system | Ibm | 2.3.3.0 (including) | 2.3.3.0 (including) |
Cloud_pak_system | Ibm | 2.3.3.3 (including) | 2.3.3.3 (including) |
Cloud_pak_system | Ibm | 2.3.3.3-ifix1 (including) | 2.3.3.3-ifix1 (including) |
Cloud_pak_system | Ibm | 2.3.3.4 (including) | 2.3.3.4 (including) |
Cloud_pak_system | Ibm | 2.3.3.5 (including) | 2.3.3.5 (including) |
Cloud_pak_system | Ibm | 2.3.3.6 (including) | 2.3.3.6 (including) |
Cloud_pak_system | Ibm | 2.3.3.6-ifix1 (including) | 2.3.3.6-ifix1 (including) |
Cloud_pak_system | Ibm | 2.3.3.6-ifix2 (including) | 2.3.3.6-ifix2 (including) |
Cloud_pak_system | Ibm | 2.3.3.7 (including) | 2.3.3.7 (including) |
Cloud_pak_system | Ibm | 2.3.3.7-ifix1 (including) | 2.3.3.7-ifix1 (including) |