VDB
CVE-2023-32335
CVE-2023-32335
PUBLISHED
Es besteht eine Schwachstelle in IBM Maximo Asset Management. Dieser Fehler besteht, weil vertrauliche Informationen in URL-Parametern gespeichert sind. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um vertrauliche Informationen offenzulegen.
EPSS 0.08% · 23.2th percentile
Risk Scores
EPSS Score
0.08%
23.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | IBM Maximo Asset Management < 7.6.1.3-TIV-MBS-IF015 |
Exploit Intelligence
- CIRCL seen: CVE-2023-32335 (circl-sighting)
- CIRCL seen: CVE-2023-32335 (circl-sighting)
- https://www.ibm.com/support/pages/node/7138684 (circl)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/266875 (circl)
- https://www.ibm.com/support/pages/node/7138686 (circl)
Timeline
- Mar 13, 2024 CVE Published
- Mar 13, 2024 PoC Published
- Mar 13, 2024 PoC Published
- Mar 14, 2024 EPSS Score
- Apr 9, 2024 EPSS Score
- May 5, 2024 EPSS Score
- May 31, 2024 EPSS Score
- Jun 26, 2024 EPSS Score
- Jul 23, 2024 EPSS Score
- Aug 18, 2024 EPSS Score
- Sep 13, 2024 EPSS Score
- Oct 9, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0634.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0634 advisory
- https://www.ibm.com/support/pages/node/7138684 advisory
- https://github.com/advisories/GHSA-2467-cw25-7vww advisory
- https://www.ibm.com/support/pages/node/7141270 advisory
- https://www.ibm.com/support/pages/node/7141493 advisory