First published: Thu Sep 07 2023(Updated: )
IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | =8.9 | |
IBM Maximo Application Suite | =8.10 | |
IBM Maximo Asset Management | =7.6.1.2 | |
IBM Maximo Asset Management | =7.6.1.3 | |
<=7.6.1.2 | ||
<=7.6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32332 is a vulnerability in IBM Maximo Application Suite and IBM Maximo Asset Management that allows remote attackers to inject malicious HTML code, which can be executed in the victim's web browser.
IBM Maximo Application Suite versions 8.9 and 8.10 are affected by CVE-2023-32332.
IBM Maximo Asset Management versions 7.6.1.2 and 7.6.1.3 are affected by CVE-2023-32332.
CVE-2023-32332 has a severity rating of 5.4 (medium).
Yes, IBM has released fixes for the affected versions of IBM Maximo Application Suite and IBM Maximo Asset Management. It is recommended to install the latest updates to mitigate the vulnerability.