High
CVE-2022-38385 CVSS:7.1
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation.
CVE-2022-38387 CVSS:7.1
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
IBM
Refer to IBM Security Bulletin for patch, upgrade or suggested workaround information.
CVE-2022-38385
CVE-2022-38387