Log Injection Vulnerability in IBM Maximo Application Suite
CVE-2024-35150
5.3MEDIUM
Summary
The IBM Maximo Application Suite experiences a vulnerability in its Monitor Component that fails to properly neutralize output sent to logs. This imperfection may enable attackers to inject deceptive entries into the log files, potentially leading to misleading information being recorded. Such an attack could compromise the integrity of the logging system, making it challenging to accurately assess the state of the application and potentially allowing further attacks.
Affected Version(s)
Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, 9.1.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved