First published: Thu Oct 20 2022(Updated: )
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | =8.7 | |
IBM Maximo Application Suite | =8.8 | |
IBM Maximo Mobile in the Maximo Application Suite | <=8.7, 8.8 | |
IBM Maximo Mobile for EAM in the Maximo Application Suite | <=8.7, 8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-41732.
The severity level of CVE-2022-41732 is medium (6.2).
IBM Maximo Mobile versions 8.7 and 8.8 are affected by CVE-2022-41732.
CVE-2022-41732 allows local users to read user credentials stored in plain clear text in IBM Maximo Mobile.
Yes, you can find references for CVE-2022-41732 at the following links: 1. [IBM X-Force ID: 237407](https://exchange.xforce.ibmcloud.com/vulnerabilities/237407) 2. [IBM Support Page](https://www.ibm.com/support/pages/node/6841617)