PT-2017-10404 · Ibm · Ibm Maximo Asset Management

Publicado

2017-06-07

·

Atualizado

2017-06-12

·

CVE-2016-9977

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management versions 7.1 through 7.6
Description The issue is caused by the failure to invalidate an existing session identifier, allowing a remote attacker to hijack a user's session. This could enable the attacker to gain access to another user's session.
Recommendations For versions 7.1 through 7.6, update the software to invalidate existing session identifiers after a user logs out to prevent session hijacking.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9977

Produtos afetados

Ibm Maximo Asset Management