IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Project Subscriptions

Vendors Products
Cloud Pak System Subscribe
Os Image For Red Hat Linux Systems Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerabilities now by http://www.ibm.com/support/docview.wss?uid=ibm10887959 For unsupported versions the recommendation is to upgrade to a supported version of the product.


Workaround

No workaround given by the vendor.

History

Wed, 25 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm os Image For Red Hat Linux Systems
CPEs cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.6.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:4.0.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:4.0.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:4.0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:4.0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:5.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:os_image_for_red_hat_linux_systems:5.0.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm os Image For Red Hat Linux Systems

Thu, 05 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple Vulnerabilities in IBM Cloud Pak System
First Time appeared Ibm
Ibm cloud Pak System
Weaknesses CWE-209
CPEs cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:ifix1:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_system:2.3.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak System
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-05T14:32:17.345Z

Reserved: 2023-07-11T17:33:12.813Z

Link: CVE-2023-38017

cve-icon Vulnrichment

Updated: 2026-02-05T14:24:53.985Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:15:56.480

Modified: 2026-02-25T15:07:25.053

Link: CVE-2023-38017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses