PT-2024-12319 · Ibm · Ibm Maximo Application Suite+1
Published
2024-03-13
·
Updated
2025-01-14
·
CVE-2023-32335
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Maximo Application Suite versions 8.10 through 8.11
IBM Maximo Asset Management version 7.6.1.3
Description
The software stores sensitive information in URL parameters, which may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Recommendations
For IBM Maximo Application Suite versions 8.10 through 8.11, consider modifying the application to avoid storing sensitive information in URL parameters.
For IBM Maximo Asset Management version 7.6.1.3, consider implementing measures to restrict access to server logs and browser history to minimize the risk of information disclosure.
As a temporary workaround, consider configuring the server to not log sensitive URL parameters until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Maximo Application Suite
Ibm Maximo Asset Management