CVE-2024-35144: IBM Maximo Application Suite information disclosure
IBM Maximo Application Suite - Monitor Component stores source code on the web server that could aid in further attacks against the system.
Other sources
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35144?
CVE-2024-35144 has a moderate severity rating due to the potential exposure of source code that could facilitate further attacks.
How do I fix CVE-2024-35144?
To remediate CVE-2024-35144, ensure you securely configure the monitor component settings to prevent unauthorized access to the web server's source code.
Which versions are affected by CVE-2024-35144?
CVE-2024-35144 affects IBM Maximo Application Suite versions 8.10, 8.11, and 9.0, specifically the Monitor Component.
What could an attacker do with the source code exposed by CVE-2024-35144?
An attacker could leverage the exposed source code to exploit vulnerabilities within the application and potentially gain unauthorized access or cause further damage.
Is there a patch available for CVE-2024-35144?
Yes, IBM has released guidance and patches to address the vulnerabilities associated with CVE-2024-35144, which should be applied promptly.