Lucene search

K
ibmIBM9793B4B63572BF069C91A2433B2E914FDB2087010DB522B9217A646BE3DB4075
HistoryMar 12, 2024 - 3:58 p.m.

Security Bulletin: IBM Maximo Mobile for EAM is vulnerable to Information Disclosure LDAP only (CVE-2023-43043)

2024-03-1215:58:34
www.ibm.com
21
ibm maximo mobile
eam
information disclosure
vulnerability
cve-2023-43043
ibm maximo application suite
maximo asset management
fix
release

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

Summary

IBM Maximo Mobile for EAM could disclose sensitive information to a local user.

Vulnerability Details

CVEID:CVE-2023-43043
**DESCRIPTION:**IBM Maximo Application Suite - Maximo Mobile for EAM could disclose sensitive information to a local user.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/266875 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s)|**Version(s)
**
—|—
IBM Maximo Mobile for EAM in the Maximo Application Suite| 8.10, 8.11

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

For Maximo Mobile for EAM:

EAM Maximo Mobile version EAM Patch Fix or Release
7.6.1.3

8.11.0

|

IBM Maximo Asset Management interim fix or latest:

8.11.0-IBM-MAXMOBILE-IFIX001

7.6.1.3|

8.10.0

|

IBM Maximo Asset Management interim fix or latest:

8.10.0-IBM-MAXMOBILE-IFIX005

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibmmaximo_application_suiteMatch8.10.0
OR
ibmmaximo_application_suiteMatch8.11.0
VendorProductVersionCPE
ibmmaximo_application_suite8.10.0cpe:2.3:a:ibm:maximo_application_suite:8.10.0:*:*:*:*:*:*:*
ibmmaximo_application_suite8.11.0cpe:2.3:a:ibm:maximo_application_suite:8.11.0:*:*:*:*:*:*:*

CVSS3

5.1

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

Related for 9793B4B63572BF069C91A2433B2E914FDB2087010DB522B9217A646BE3DB4075