CVE-2023-38265: IBM Cloud Pak System

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

Affected products

  • IBM Cloud Pak System: version 2.3.3.6 only; version 2.3.3.7 only; version 2.3.4.0 only; version 2.3.4.1 only; version 2.3.5.0 only

Published 2026-02-17. Last modified 2026-06-17.