CVE-2023-38007: IBM Cloud Pak System

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Affected products

  • IBM Cloud Pak System: version 2.3.3.6 only; version 2.3.3.7 only; version 2.3.4.0 only; version 2.3.4.1 only; version 2.3.5.0 only

Published 2025-06-27. Last modified 2026-06-17.