Cloud Pak System

Vendor:

First CVE: Dec 3, 2019 · Active for 6 years

36
Total CVEs
More Total CVEs than 97% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cloud Pak System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2019
6 years ago
Most Recent CVE
Feb 17, 2026
157 days ago

CVE Severity & Scoring

Cloud Pak System36 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local6 (16.7%)
Network30 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (69.4%)
Unknown0 (0.0%)
Required11 (30.6%)
Privileges Required
Low13 (36.1%)
High8 (22.2%)
None15 (41.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper
Dec 10, 20199.830NONO
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IB
May 9, 20227.525NONO
IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM
Dec 3, 20198.825NONO
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
Feb 4, 20267.524NONO
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive information about the system that could aid in further attac
Jan 25, 20257.523NONO
IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.
Jan 4, 20217.223NONO
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with
Mar 27, 20257.522NONO
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we
Jan 4, 20218.822NONO
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information about
Jan 25, 20257.521NONO
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could disclose sensitive information in HT
Jan 25, 20257.521NONO

Exploit Exposure

Signals from CVEs in this product scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (36 CVEs).

Media Mentions

Signals from CVEs in this product scope (36 CVEs).

Top CNAs Publishing CVEs For Cloud Pak System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.6.036.00.3%00
2.3.5.065.50.3%00
2.3.4.195.80.3%00
2.3.4.0115.90.3%00
2.3.3.7136.50.3%00
2.3.3.6126.60.3%00
2.3.3.567.20.3%00
2.3.3.467.20.3%00
2.3.3.367.20.3%00
2.3.3.067.20.3%00
2.3.2.017.50.7%00
2.3.1.137.20.4%00
2.3.0.186.00.9%00
2.3.0.017.50.3%00
2.395.70.9%00