CVE-2024-35145: IBM Maximo Application Suite cross-site scripting
IBM Maximo Application Suite - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35145?
The severity of CVE-2024-35145 is classified as medium due to its potential impact on user interactions.
How do I fix CVE-2024-35145?
To fix CVE-2024-35145, apply the latest security updates provided by IBM for the Maximo Application Suite.
Who is affected by CVE-2024-35145?
Users of IBM Maximo Application Suite, specifically those using the Monitor Component up to version 9.0.0, are affected by CVE-2024-35145.
What type of attack can exploit CVE-2024-35145?
CVE-2024-35145 can be exploited through a cross-site scripting (XSS) attack, allowing for arbitrary JavaScript code execution.
Can CVE-2024-35145 lead to credential theft?
Yes, CVE-2024-35145 has the potential to lead to credential disclosure if exploited by embedding malicious scripts in the web interface.