CVE-2024-22333
13.06.2024, 14:15
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 279973.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | maximo_application_suite | 8.10 |
ibm | maximo_application_suite | 8.11 |
ibm | maximo_asset_management | 7.6.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-525 - Use of Web Browser Cache Containing Sensitive InformationThe web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References