First published: Wed Nov 06 2024(Updated: )
IBM Maximo Application Suite - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Application Suite | ||
IBM Maximo Application Suite | <=9.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-35145 is classified as medium due to its potential impact on user interactions.
To fix CVE-2024-35145, apply the latest security updates provided by IBM for the Maximo Application Suite.
Users of IBM Maximo Application Suite, specifically those using the Monitor Component up to version 9.0.0, are affected by CVE-2024-35145.
CVE-2024-35145 can be exploited through a cross-site scripting (XSS) attack, allowing for arbitrary JavaScript code execution.
Yes, CVE-2024-35145 has the potential to lead to credential disclosure if exploited by embedding malicious scripts in the web interface.