CVE-2024-22328: IBM Maximo Application Suite information disclosure
IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.
Other sources
IBM Maximo Application Suite could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22328?
CVE-2024-22328 is classified as a high severity vulnerability that allows directory traversal in IBM Maximo Application Suite.
How do I fix CVE-2024-22328?
To fix CVE-2024-22328, it is recommended to patch IBM Maximo Application Suite to the latest version that addresses this vulnerability.
What impacts does CVE-2024-22328 have on IBM Maximo Application Suite?
CVE-2024-22328 can allow attackers to view arbitrary files on the system through specially crafted URL requests, posing significant security risks.
Which versions of IBM Maximo Application Suite are affected by CVE-2024-22328?
CVE-2024-22328 affects IBM Maximo Application Suite versions 8.10.0 and up to 8.11.0.
Can CVE-2024-22328 be exploited remotely?
Yes, CVE-2024-22328 can be exploited remotely by an attacker using crafted URL requests to traverse directories.