CVE-2022-41734
17.02.2023, 18:15
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | maximo_application_suite | 8.4 |
ibm | maximo_application_suite | 8.5 |
ibm | maximo_asset_management | 7.6.1.2 |
ibm | maximo_asset_management | 7.6.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.