CVE-2023-37405: IBM Cloud Pak System

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.

Affected products

  • IBM Cloud Pak System: version 2.3.1.1 only; version 2.3.3.0 only; version 2.3.3.3 only; version 2.3.3.4 only; version 2.3.3.5 only; version 2.3.3.6 only; …
  • IBM Cloud Pak System Software Suite: version 2.3.2.0 only

Published 2025-03-27. Last modified 2026-06-17.