PT-2012-1965 · Ibm · Asset Management Essentials+1

Publicado

2012-03-13

·

Atualizado

2018-01-10

·

CVE-2011-4818

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management and Asset Management Essentials versions 6.2, 7.1, and 7.5
Description The issue allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component. This enables potential phishing attacks.
Recommendations For versions 6.2, 7.1, and 7.5, consider restricting access to the component that utilizes the uisessionid parameter until a fix is available. Avoid using the uisessionid parameter in affected components to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4818

Produtos afetados

Asset Management Essentials
Ibm Maximo Asset Management