CVE-2023-32335: IBM Maximo Application Suite information disclosure
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.
Other sources
IBM Maximo Asset Management stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32335?
The severity of CVE-2023-32335 is categorized as a medium risk due to potential information disclosure.
How do I fix CVE-2023-32335?
To fix CVE-2023-32335, ensure sensitive information is not stored in URL parameters and consider implementing better access controls.
What types of systems are affected by CVE-2023-32335?
CVE-2023-32335 affects IBM Maximo Application Suite versions 8.10, 8.11 and IBM Maximo Asset Management version 7.6.1.3.
What can happen if CVE-2023-32335 is exploited?
If CVE-2023-32335 is exploited, unauthorized parties may gain access to sensitive information through URL parameters.
Is there a known workaround for CVE-2023-32335?
There is no specific workaround for CVE-2023-32335 other than following best practices to avoid exposing sensitive data.