First published: Wed Jan 04 2023(Updated: )
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | =8.3 | |
IBM Maximo Application Suite | =8.4 | |
IBM Maximo Asset Management | =7.6.1.1 | |
IBM Maximo Asset Management | =7.6.1.2 | |
IBM Maximo Asset Management | =7.6.1.3 | |
IBM Maximo Asset Management | <=7.6.1.1 | |
IBM Maximo Asset Management | <=7.6.1.2 | |
IBM Maximo Asset Management | <=7.6.1.3 | |
IBM Maximo Application Suite - Manage Component | <=8.3 | |
IBM Maximo Application Suite - Manage Component | <=8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-35281 is high.
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are affected by CVE-2022-35281.
CSV injection is a vulnerability that allows an attacker to inject malicious content into a CSV (Comma Separated Values) file, which can be exploited to execute arbitrary code or perform unauthorized actions.
IBM has released a security advisory for CVE-2022-35281 which includes instructions to apply the necessary fixes or patches.
More information about CVE-2022-35281 can be found on the IBM X-Force Exchange website and the official IBM support page.