CVE-2022-38383

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:cloud_pak_for_security:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_suite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:16

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/233673 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/233673 - VDB Entry
References () https://www.ibm.com/support/pages/node/7158986 - Vendor Advisory () https://www.ibm.com/support/pages/node/7158986 - Vendor Advisory
CVSS v2 : unknown
v3 : 3.3
v2 : unknown
v3 : 4.0

01 Aug 2024, 17:57

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Ibm
Ibm cloud Pak For Security
Ibm qradar Suite
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/233673 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/233673 - VDB Entry
References () https://www.ibm.com/support/pages/node/7158986 - () https://www.ibm.com/support/pages/node/7158986 - Vendor Advisory
CPE cpe:2.3:a:ibm:cloud_pak_for_security:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:qradar_suite:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 4.0
v2 : unknown
v3 : 3.3

01 Jul 2024, 12:37

Type Values Removed Values Added
Summary
  • (es) IBM Cloud Pak for Security (CP4S) 1.10.0.0 a 1.10.11.0 e IBM QRadar Software Suite 1.10.12.0 a 1.10.21.0 permiten almacenar localmente páginas web que pueden ser leídas por otro usuario en el sistema. ID de IBM X-Force: 233673.

28 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 19:15

Updated : 2024-11-21 07:16


NVD link : CVE-2022-38383

Mitre link : CVE-2022-38383

CVE.ORG link : CVE-2022-38383


JSON object : View

Products Affected

ibm

  • cloud_pak_for_security
  • qradar_suite
CWE
CWE-525

Use of Web Browser Cache Containing Sensitive Information

NVD-CWE-noinfo