PT-2024-13478 · Ibm · Ibm Maximo Asset Management

Published

2024-01-18

·

Updated

2024-01-24

·

CVE-2023-47718

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management version 7.6.1.3 Manage Component versions 8.10 through 8.11
Description The issue allows an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts due to cross-site request forgery.
Recommendations For IBM Maximo Asset Management version 7.6.1.3, update to a version that includes a fix for this issue. For Manage Component versions 8.10 through 8.11, update to a version that includes a fix for this issue. As a temporary workaround, consider implementing additional validation for requests to prevent unauthorized actions.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47718

Affected Products

Ibm Maximo Asset Management