Lucene search

K
ibmIBMB2338198766776E2345DCAD799BED4770E1464124DE3E7FE3416B1A84CCE9CA0
HistoryJan 26, 2024 - 10:02 p.m.

Security Bulletin: IBM Maximo Spatial Asset Management is vulnerable to Blind Server-Side Request Forgery (CVE-2023-32337)

2024-01-2622:02:48
www.ibm.com
17
ibm
maximo
spatial asset management
ssrf
vulnerability
cve-2023-32337
server-side request forgery
update
fix
download
interim fix

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Summary

IBM Maximo Spatial Asset Management is vulnerable to Blind Server-Side Request Forgery

Vulnerability Details

CVEID:CVE-2023-32337
**DESCRIPTION:**IBM Maximo Spatial Asset Management is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/255288 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

This vulnerability affects the following versions of the IBM Maximo Asset Management core product. The recommended action is to update to the latest version.

Affected Product(s) Version(s)
IBM Maximo Spatial Asset Management 7.6.1.0
IBM Maximo Spatial Asset Management 7.6.1.1
  • To determine the core product version, log in and view System Information. The core product version is the β€œTivoli’s process automation engine” version. Please consult the Platform Matrix for a list of supported product combinations.

Remediation/Fixes

The recommended solution is to download the appropriate Interim Fix or Fix Pack from Fix Central and apply for each affected product as soon as possible. Please see below for information on the fixes available for each product, version, and release. Follow the installation instructions in the β€˜readme’ documentation provided with each fix pack or interim fix.

For IBM Maximo Spatial Asset Management in Maximo Asset Management 7.6:

VRM Maximo Asset Management Fix Pack, Feature Pack, or Interim Fix IBM Maximo Spatial Asset Management Fix Pack, Feature Pack, or Interim Fix Download
7.6.1.2

Maximo Asset Management 7.6.1.2 iFix:
7.6.1.2-TIV-MBS-IFI039 or latest Interim Fix available

|

IBM Maximo Spatial Asset Management iFix: 7.6.1.0-TIV-MAMST-IF027 or latest Interim Fix available

| FixCentral
7.6.1.3|

Maximo Asset Management 7.6.1.3 iFix:

7.6.1.3-TIV-MBS-IF012 or latest Interim Fix available

|

IBM Maximo Spatial Asset Management iFix: 7.6.1.1-TIV-MAMST-IF010 or latest Interim Fix available

|

FixCentral

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmaximo_spatial_asset_managementMatch7.6.1
CPENameOperatorVersion
maximo spatial asset managementeq7.6.1

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Related for B2338198766776E2345DCAD799BED4770E1464124DE3E7FE3416B1A84CCE9CA0