Lucene search

K
ibmIBM25BEFB09F072B88FE43AA4F8088C55095DADC22101A69C20E7804F5A11003BE1
HistorySep 09, 2024 - 8:17 a.m.

Security Bulletin: IBM Maximo Application Suite - Predict Component component uses urllib3-1.26.18-py2.py3-none-any.whl which is vulnerable to this CVE-2024-37891

2024-09-0908:17:10
www.ibm.com
3
ibm maximo application suite
predict component
urllib3
vulnerability
cve-2024-37891
sensitive information
cvss
remediation
version 9.0.1

CVSS3

4.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

Low

Summary

IBM Maximo Application Suite - Predict Component component uses urllib3-1.26.18-py2.py3-none-any.whl which is vulnerable to this CVE-202437891

Vulnerability Details

CVEID:CVE-2024-37891
**DESCRIPTION:**urllib3 could allow a remote authenticated attacker to obtain sensitive information, caused by the failure to strip the Proxy-Authorization header during cross-origin redirects. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 4.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/295053 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Maximo Application Suite - Predict Component 9.0.0

Remediation/Fixes

Affected Product(s) Version(s)
IBM Maximo Application Suite - Predict Component 9.0.1

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximoMatch9.0.0
VendorProductVersionCPE
ibmmaximo9.0.0cpe:2.3:a:ibm:maximo:9.0.0:*:*:*:*:*:*:*

CVSS3

4.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

Low