CVE-2023-38273: IBM Cloud Pak System
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
Affected products
- IBM Cloud Pak System: from 2.3.3.0, up to and including 2.3.3.6; version 2.3.1.1 only; version 2.3.2.0 only; version 2.3.3.7 only
Published 2024-02-02. Last modified 2026-06-17.