IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection.  IBM X-Force ID:  2306335.
                
            References
                    | Link | Resource | 
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/230635 | VDB Entry Vendor Advisory | 
| https://www.ibm.com/support/pages/node/6852669 | Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/230635 | VDB Entry Vendor Advisory | 
| https://www.ibm.com/support/pages/node/6852669 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 07:11
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/230635 - VDB Entry, Vendor Advisory | |
| References | () https://www.ibm.com/support/pages/node/6852669 - Vendor Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.5  | 
07 Nov 2023, 03:48
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335. | 
Information
                Published : 2023-01-09 08:15
Updated : 2024-11-21 07:11
NVD link : CVE-2022-35281
Mitre link : CVE-2022-35281
CVE.ORG link : CVE-2022-35281
JSON object : View
Products Affected
                ibm
- maximo_asset_management
 - maximo_application_suite
 
CWE
                
                    
                        
                        CWE-1236
                        
            Improper Neutralization of Formula Elements in a CSV File
