Lucene search

K
ibmIBM838491604B19E08079C8517A0557BF7C1F1F0679AAB2FCE512F67D3D85D7CCC2
HistoryJan 15, 2024 - 5:30 p.m.

Security Bulletin: IBM Maximo Manage application in IBM Maximo Application Suite is vulnerable to Blind Server-Side Request Forgery (CVE-2023-32337)

2024-01-1517:30:08
www.ibm.com
7
ibm maximo manage
blind server-side request forgery
vulnerability
ibm maximo application suite
ibm maximo spatial
manage component
mas 8.10.0
patches
upgrade

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Summary

IBM Maximo Manage application in IBM Maximo Application Suite is vulnerable to Blind Server-Side Request Forgery (CVE-2023-32337)

Vulnerability Details

CVEID:CVE-2023-32337
**DESCRIPTION:**IBM Maximo Spatial Asset Management is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/255288 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Maximo Spatial in IBM Maximo Application Suite - Manage Component

MAS 8.10.0 - Manage 8.6.0 - Spatial 8.6.0

Remediation/Fixes

For IBM Maximo Spatial in IBM Maximo Application Suite - Manage Component:

MAS Manage Patch Fix or Release Spatial Patch Fix or Release
Upgrade to MAS 8.10.X

Upgrade to Manage 8.6.4 or latest (available from the Catalog under Update Available)

|

Upgrade to Spatial 8.6.4 or latest (available from the Catalog under Update Available)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch8.10
CPENameOperatorVersion
ibm maximo application suiteeq8.10

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Related for 838491604B19E08079C8517A0557BF7C1F1F0679AAB2FCE512F67D3D85D7CCC2