Cloud Pak System
Vendor:
First CVE: Dec 3, 2019 · Active for 6 years
36
Total CVEs
More Total CVEs than 97% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Pak System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2019
6 years ago
Most Recent CVE
Feb 17, 2026
157 days ago
CVE Severity & Scoring
Cloud Pak System36 CVEs
8%
58%
31%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (16.7%)
Network30 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (69.4%)
Unknown0 (0.0%)
Required11 (30.6%)
Privileges Required
Low13 (36.1%)
High8 (22.2%)
None15 (41.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4521CRITICAL Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper | Dec 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-20479HIGH IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IB | May 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-4130HIGH IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM | Dec 3, 2019 | 8.8 | 25 | NO | NO |
CVE-2023-38010HIGH IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system. | Feb 4, 2026 | 7.5 | 24 | NO | NO |
CVE-2023-38716HIGH IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further attac | Jan 25, 2025 | 7.5 | 23 | NO | NO |
CVE-2020-4912HIGH IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287. | Jan 4, 2021 | 7.2 | 23 | NO | NO |
CVE-2023-38272HIGH IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1
could allow a user with | Mar 27, 2025 | 7.5 | 22 | NO | NO |
CVE-2020-4917HIGH IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we | Jan 4, 2021 | 8.8 | 22 | NO | NO |
CVE-2023-38714HIGH IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about | Jan 25, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-38013HIGH IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HT | Jan 25, 2025 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Cloud Pak System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.6.0 | 3 | 6.0 | 0.3% | 0 | 0 |
| 2.3.5.0 | 6 | 5.5 | 0.3% | 0 | 0 |
| 2.3.4.1 | 9 | 5.8 | 0.3% | 0 | 0 |
| 2.3.4.0 | 11 | 5.9 | 0.3% | 0 | 0 |
| 2.3.3.7 | 13 | 6.5 | 0.3% | 0 | 0 |
| 2.3.3.6 | 12 | 6.6 | 0.3% | 0 | 0 |
| 2.3.3.5 | 6 | 7.2 | 0.3% | 0 | 0 |
| 2.3.3.4 | 6 | 7.2 | 0.3% | 0 | 0 |
| 2.3.3.3 | 6 | 7.2 | 0.3% | 0 | 0 |
| 2.3.3.0 | 6 | 7.2 | 0.3% | 0 | 0 |
| 2.3.2.0 | 1 | 7.5 | 0.7% | 0 | 0 |
| 2.3.1.1 | 3 | 7.2 | 0.4% | 0 | 0 |
| 2.3.0.1 | 8 | 6.0 | 0.9% | 0 | 0 |
| 2.3.0.0 | 1 | 7.5 | 0.3% | 0 | 0 |
| 2.3 | 9 | 5.7 | 0.9% | 0 | 0 |