First published: Tue Mar 12 2024(Updated: )
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | =8.10 | |
IBM Maximo Application Suite | =8.11 | |
IBM Maximo Asset Management | =7.6.1.3 | |
IBM Maximo Manage Application | <=MAS 8.10.0 - Manage 8.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-32335 is categorized as a medium risk due to potential information disclosure.
To fix CVE-2023-32335, ensure sensitive information is not stored in URL parameters and consider implementing better access controls.
CVE-2023-32335 affects IBM Maximo Application Suite versions 8.10, 8.11 and IBM Maximo Asset Management version 7.6.1.3.
If CVE-2023-32335 is exploited, unauthorized parties may gain access to sensitive information through URL parameters.
There is no specific workaround for CVE-2023-32335 other than following best practices to avoid exposing sensitive data.