TROYANOSYVIRUS
Back to CVEs

CVE-2023-32335

LOW
3.7

Description

IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.

CVE Details

CVSS v3.1 Score3.7
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published3/13/2024
Last Modified1/14/2025
Sourcenvd
Honeypot Sightings0

Affected Products

ibm:maximo_application_suiteibm:maximo_asset_management

Weaknesses (CWE)

CWE-598

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.