CVE-2022-22435: XSS
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM Maximo Asset Management?
The vulnerability ID for IBM Maximo Asset Management is CVE-2022-22435.
What is the severity of CVE-2022-22435?
The severity of CVE-2022-22435 is medium, with a CVSS score of 5.4.
What is the description of CVE-2022-22435?
CVE-2022-22435 is a cross-site scripting vulnerability in IBM Maximo Asset Management 7.6.1.2 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Which software versions are affected by CVE-2022-22435?
IBM Maximo Asset Management 7.6.1.2 and previous versions are affected by CVE-2022-22435.
How can I fix CVE-2022-22435?
To fix CVE-2022-22435, apply the necessary patches or updates provided by IBM.