CVE-2022-41732: IBM Maximo information disclosure
Published Oct 20, 2022
·Updated
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407.
Other sources
IBM Maximo Mobile stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
4 affected components
IBM Maximo Mobile in the Maximo Application Suite<=8.7, 8.8
IBM Maximo Mobile for EAM in the Maximo Application Suite<=8.7, 8.8
IBM Maximo Application Suite=8.7
IBM Maximo Application Suite=8.8
Event History
Oct 20, 2022
CVE Published
via IBM·12:00 AM
Nov 28, 2022
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41732.
2
What is the severity level of CVE-2022-41732?
The severity level of CVE-2022-41732 is medium (6.2).
3
Which software versions are affected by CVE-2022-41732?
IBM Maximo Mobile versions 8.7 and 8.8 are affected by CVE-2022-41732.
4
How does CVE-2022-41732 impact the affected software?
CVE-2022-41732 allows local users to read user credentials stored in plain clear text in IBM Maximo Mobile.
5
Are there any references available for CVE-2022-41732?
Yes, you can find references for CVE-2022-41732 at the following links: 1. [IBM X-Force ID: 237407](https://exchange.xforce.ibmcloud.com/vulnerabilities/237407) 2. [IBM Support Page](https://www.ibm.com/support/pages/node/6841617)