CVE-2023-32337: IBM Maximo Spatial Asset Management server-side request forgery
IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 255288.
Other sources
IBM Maximo Spatial Asset Management is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32337?
CVE-2023-32337 is considered a medium severity vulnerability due to the potential for server-side request forgery resulting in unauthorized requests.
How do I fix CVE-2023-32337?
To fix CVE-2023-32337, you should apply the latest patches provided by IBM for the affected versions of Maximo Spatial Asset Management.
Who is affected by CVE-2023-32337?
CVE-2023-32337 affects users of IBM Maximo Spatial Asset Management versions 8.10 and below.
What are the potential impacts of CVE-2023-32337?
The potential impacts of CVE-2023-32337 include unauthorized access to network resources and the possibility of further attacks on the system.
Is there a workaround for CVE-2023-32337?
A recommended workaround for CVE-2023-32337 is to implement network segmentation and restrict access to sensitive internal services.