Impact
The vulnerability allows a local attacker to collect credential data that the IBM Cloud Pak System records in its log files. Because the system writes authentication data in clear text, an attacker who can read the logs can obtain privileged usernames and passwords. This defect is a manifestation of the weakness CWE‑798, which arises when the product does not protect sensitive information during storage or transmission.
Affected Systems
IBM Cloud Pak System version 2.3.5.0 is vulnerable. The advisory also notes that unsupported versions should be upgraded to a supported release. No other product versions are listed as affected in the current data.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability falls in the high severity range. The EPSS score is less than 1%, indicating that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local system access to read the log files, making the attack vector a local privilege or compromise scenario.
OpenCVE Enrichment