CVE-2023-32332: IBM Maximo Application Suite and IBM Maximo Asset Management HTML injection
IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072.
Other sources
IBM Maximo Application Suite is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32332?
CVE-2023-32332 is a vulnerability in IBM Maximo Application Suite and IBM Maximo Asset Management that allows remote attackers to inject malicious HTML code, which can be executed in the victim's web browser.
Which versions of IBM Maximo Application Suite are affected by CVE-2023-32332?
IBM Maximo Application Suite versions 8.9 and 8.10 are affected by CVE-2023-32332.
Which versions of IBM Maximo Asset Management are affected by CVE-2023-32332?
IBM Maximo Asset Management versions 7.6.1.2 and 7.6.1.3 are affected by CVE-2023-32332.
How severe is CVE-2023-32332?
CVE-2023-32332 has a severity rating of 5.4 (medium).
Is there a fix available for CVE-2023-32332?
Yes, IBM has released fixes for the affected versions of IBM Maximo Application Suite and IBM Maximo Asset Management. It is recommended to install the latest updates to mitigate the vulnerability.