CVE Vulnerabilities

CVE-2023-38265

Exposure of Information Through Directory Listing

Published: Feb 17, 2026 | Modified: Feb 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Cloud_pak_systemIbm2.3.3.6 (including)2.3.3.6 (including)
Cloud_pak_systemIbm2.3.3.7 (including)2.3.3.7 (including)
Cloud_pak_systemIbm2.3.4.0 (including)2.3.4.0 (including)
Cloud_pak_systemIbm2.3.4.1 (including)2.3.4.1 (including)
Cloud_pak_systemIbm2.3.5.0 (including)2.3.5.0 (including)

Potential Mitigations

References