CVE-2023-32334: IBM Maximo Asset Management information disclosure
IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.
Other sources
IBM Maximo Asset Management stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32334.
What is the severity of CVE-2023-32334?
The severity of CVE-2023-32334 is medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2023-32334?
IBM Maximo Asset Management versions 7.6.1.2 and 7.6.1.3, and IBM Maximo Application Suite version 8.8.0 are affected by CVE-2023-32334.
What is the potential impact of CVE-2023-32334?
CVE-2023-32334 may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, or browser history.
Are there any references available for CVE-2023-32334?
Yes, you can find more information about CVE-2023-32334 at the following references: - [IBM X-Force ID: 255074](https://exchange.xforce.ibmcloud.com/vulnerabilities/255074) - [IBM Support Page 1](https://www.ibm.com/support/pages/node/6999721) - [IBM Support Page 2](https://www.ibm.com/support/pages/node/6999747)