First published: Wed Mar 29 2023(Updated: )
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 249327.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.6.1.2 | |
IBM Maximo Asset Management | =7.6.1.3 | |
<=7.6.1.2 | ||
<=7.6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM Maximo Asset Management is CVE-2023-27864.
The severity of CVE-2023-27864 is medium, with a severity value of 5.4.
The HTML injection vulnerability in IBM Maximo Asset Management allows a remote attacker to inject malicious HTML code that is executed in the victim's web browser within the security context of the hosting site.
IBM Maximo Asset Management versions 7.6.1.2 and 7.6.1.3 are affected by CVE-2023-27864.
To fix the HTML injection vulnerability in IBM Maximo Asset Management, it is recommended to apply the latest security patches provided by IBM.