PT-2024-12319 · Ibm · Ibm Maximo Application Suite+1

Published

2024-03-13

·

Updated

2025-01-14

·

CVE-2023-32335

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Maximo Application Suite versions 8.10 through 8.11 IBM Maximo Asset Management version 7.6.1.3
Description The software stores sensitive information in URL parameters, which may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Recommendations For IBM Maximo Application Suite versions 8.10 through 8.11, consider modifying the application to avoid storing sensitive information in URL parameters. For IBM Maximo Asset Management version 7.6.1.3, consider implementing measures to restrict access to server logs and browser history to minimize the risk of information disclosure. As a temporary workaround, consider configuring the server to not log sensitive URL parameters until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-32335

Affected Products

Ibm Maximo Application Suite
Ibm Maximo Asset Management