Cloud Pak System
IBM · 37 CVEs
Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []
Jul 28, 2026
Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak Syst…
Feb 17, 2026
Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak Syst…
Feb 17, 2026
Multiple Vulnerabilities in IBM Cloud Pak System
Feb 4, 2026
Multiple Vulnerabilities in IBM Cloud Pak System
Feb 4, 2026
Multiple Vulnerabilities in IBM Cloud Pak System
Feb 4, 2026
IBM Cloud Pak System HTML injection
Jun 30, 2025
IBM Cloud Pak System HTML injection
Jun 27, 2025
IBM Cloud Pak System information disclosure
Mar 27, 2025
IBM Cloud Pak System information disclosure
Mar 27, 2025
IBM Cloud Pak System information disclosure
Jan 25, 2025
IBM Cloud Pak System information disclosure
Jan 25, 2025
IBM Cloud Pak System information disclosure
Jan 25, 2025
IBM Cloud Pak System information disclosure
Jan 25, 2025
IBM Cloud Pak System directory traversal
Jan 25, 2025
IBM Cloud Pak System information disclosure
Jan 25, 2025
IBM Cloud Pak System information disclosure
Feb 2, 2024
IBM Cloud Pak System Software Suite session fixation
May 5, 2023
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could…
May 9, 2022
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self serv…
Jul 20, 2021
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request…
Jan 4, 2021
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to imperso…
Jan 4, 2021
IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direc…
Jan 4, 2021
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious…
Jan 4, 2021
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java…
Jan 4, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-13463 | Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability [] | HIGH | 0.38% | Jul 28, 2026 |
| CVE-2023-38005 | Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] | MEDIUM | 0.21% | Feb 17, 2026 |
| CVE-2023-38265 | Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ] | MEDIUM | 0.21% | Feb 17, 2026 |
| CVE-2023-38281 | Multiple Vulnerabilities in IBM Cloud Pak System | MEDIUM | 0.32% | Feb 4, 2026 |
| CVE-2023-38017 | Multiple Vulnerabilities in IBM Cloud Pak System | MEDIUM | 0.32% | Feb 4, 2026 |
| CVE-2023-38010 | Multiple Vulnerabilities in IBM Cloud Pak System | HIGH | 0.33% | Feb 4, 2026 |
| CVE-2025-2895 | IBM Cloud Pak System HTML injection | MEDIUM | 0.25% | Jun 30, 2025 |
| CVE-2023-38007 | IBM Cloud Pak System HTML injection | MEDIUM | 0.25% | Jun 27, 2025 |
| CVE-2023-38272 | IBM Cloud Pak System information disclosure | HIGH | 0.35% | Mar 27, 2025 |
| CVE-2023-37405 | IBM Cloud Pak System information disclosure | MEDIUM | 0.23% | Mar 27, 2025 |
| CVE-2023-38271 | IBM Cloud Pak System information disclosure | MEDIUM | 0.32% | Jan 25, 2025 |
| CVE-2023-38713 | IBM Cloud Pak System information disclosure | HIGH | 0.33% | Jan 25, 2025 |
| CVE-2023-38714 | IBM Cloud Pak System information disclosure | HIGH | 0.33% | Jan 25, 2025 |
| CVE-2023-38013 | IBM Cloud Pak System information disclosure | HIGH | 0.33% | Jan 25, 2025 |
| CVE-2023-38012 | IBM Cloud Pak System directory traversal | MEDIUM | 0.50% | Jan 25, 2025 |
| CVE-2023-38716 | IBM Cloud Pak System information disclosure | HIGH | 0.33% | Jan 25, 2025 |
| CVE-2023-38273 | IBM Cloud Pak System information disclosure | HIGH | 0.67% | Feb 2, 2024 |
| CVE-2020-4914 | IBM Cloud Pak System Software Suite session fixation | MEDIUM | 0.15% | May 5, 2023 |
| CVE-2021-20479 | IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens… | HIGH | 0.66% | May 9, 2022 |
| CVE-2021-20478 | IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497. | LOW | 0.24% | Jul 20, 2021 |
| CVE-2020-4928 | IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the a… | MEDIUM | 0.37% | Jan 4, 2021 |
| CVE-2020-4919 | IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-F… | LOW | 0.63% | Jan 4, 2021 |
| CVE-2020-4918 | IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service conso… | MEDIUM | 0.30% | Jan 4, 2021 |
| CVE-2020-4917 | IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted fr… | HIGH | 0.43% | Jan 4, 2021 |
| CVE-2020-4916 | IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering… | MEDIUM | 0.66% | Jan 4, 2021 |
Showing 1 to 25 of 37 CVEs