{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-10T18:23:16.120","vulnerabilities":[{"cve":{"id":"CVE-2023-38007","sourceIdentifier":"psirt@us.ibm.com","published":"2025-06-27T15:15:24.623","lastModified":"2025-08-14T01:12:31.570","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site."},{"lang":"es","value":"IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 en Power y 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 en sistemas operativos Intel es vulnerable a la inyección de HTML. Un atacante remoto podría inyectar código HTML malicioso que, al visualizarse, se ejecutaría en el navegador web de la víctima dentro del contexto de seguridad del sitio web que lo aloja."}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:-:*:*:*:*:*:*","matchCriteriaId":"E929D5FD-319D-45FD-85FF-688528762615"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:ifix1:*:*:*:*:*:*","matchCriteriaId":"31C15792-C94C-4599-B32A-287A5B7749A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.3.6:ifix2:*:*:*:*:*:*","matchCriteriaId":"C056670B-C13D-4E6F-AB80-950A09915DB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:-:*:*:*:*:*:*","matchCriteriaId":"6AB3D285-C45A-4463-80B1-17A9B6086439"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:ifix1:*:*:*:*:*:*","matchCriteriaId":"1AC8B844-D88C-4029-8395-A73853195EC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.4.0:-:*:*:*:*:*:*","matchCriteriaId":"1A007FD5-CF3B-4DC0-B8C0-3D04AF411FD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.4.1:-:*:*:*:*:*:*","matchCriteriaId":"618F4D77-242C-415C-AA3F-4F79C2663178"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:cloud_pak_system:2.3.5.0:-:*:*:*:*:*:*","matchCriteriaId":"118829A2-1826-41FE-9F64-698B8FBCF8BB"}]}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7237162","source":"psirt@us.ibm.com","tags":["Vendor Advisory"]}]}}]}