Description
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
Published: 2026-07-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a local attacker to collect credential data that the IBM Cloud Pak System records in its log files. Because the system writes authentication data in clear text, an attacker who can read the logs can obtain privileged usernames and passwords. This defect is a manifestation of the weakness CWE‑798, which arises when the product does not protect sensitive information during storage or transmission.

Affected Systems

IBM Cloud Pak System version 2.3.5.0 is vulnerable. The advisory also notes that unsupported versions should be upgraded to a supported release. No other product versions are listed as affected in the current data.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability falls in the high severity range. The EPSS score is less than 1%, indicating that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local system access to read the log files, making the attack vector a local privilege or compromise scenario.

Generated by OpenCVE AI on August 3, 2026 at 14:13 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by https://www.ibm.com/support/pages/node/7274228 For unsupported versions the recommendation is  to upgrade to supported version of the product.


OpenCVE Recommended Actions

  • Apply the IBM patch described at https://www.ibm.com/support/pages/node/7274228
  • Upgrade any unsupported IBM Cloud Pak System installations to a supported version as recommended by IBM
  • Configure the system and applications to avoid logging credentials in plain text; ensure logs are sanitized or encrypted

Generated by OpenCVE AI on August 3, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
Title Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []
First Time appeared Ibm
Ibm cloud Pak System
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak System
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak System
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T13:56:49.921Z

Reserved: 2026-06-26T20:09:45.350Z

Link: CVE-2026-13463

cve-icon Vulnrichment

Updated: 2026-07-29T13:56:46.123Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T21:17:25.533

Modified: 2026-07-30T14:08:40.373

Link: CVE-2026-13463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:15:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials