CVE-2024-35146: IBM Maximo Application Suite cross-site scripting
IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Maximo Application Suite - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35146?
CVE-2024-35146 is rated as a high-severity cross-site scripting vulnerability allowing unauthorized code execution.
How do I fix CVE-2024-35146?
To fix CVE-2024-35146, upgrade to the latest version of IBM Maximo Application Suite - Monitor Component that addresses this vulnerability.
Who is affected by CVE-2024-35146?
CVE-2024-35146 affects users of IBM Maximo Application Suite - Monitor Component versions 8.10.11, 8.11.8, and 9.0.0.
What types of attack are possible with CVE-2024-35146?
CVE-2024-35146 allows attackers to perform cross-site scripting, potentially leading to session hijacking and data theft.
Is CVE-2024-35146 exploitable without authentication?
Yes, CVE-2024-35146 can be exploited by unauthenticated attackers, making it particularly dangerous.