CVE-2023-47718: IBM Maximo Asset Management cross-site request forgery
IBM Maximo Application Suite is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47718?
CVE-2023-47718 is classified as a high severity vulnerability due to the potential for cross-site request forgery attacks.
How do I fix CVE-2023-47718?
To fix CVE-2023-47718, users should apply the latest security patch provided by IBM for the Maximo Application Suite.
What software versions are affected by CVE-2023-47718?
CVE-2023-47718 affects IBM Maximo Application Suite - Manage Component versions 8.10 through 8.11 and IBM Maximo Asset Management version 7.6.1.3.
What type of attack does CVE-2023-47718 allow?
CVE-2023-47718 allows attackers to perform cross-site request forgery, executing unauthorized actions as trusted users.
Is CVE-2023-47718 a remote vulnerability?
Yes, CVE-2023-47718 allows remote attackers to exploit the vulnerability without needing physical access to the system.