PT-2012-1965 · Ibm · Asset Management Essentials+1

Published

2012-03-13

·

Updated

2018-01-10

·

CVE-2011-4818

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management and Asset Management Essentials versions 6.2, 7.1, and 7.5
Description The issue allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component. This enables potential phishing attacks.
Recommendations For versions 6.2, 7.1, and 7.5, consider restricting access to the component that utilizes the uisessionid parameter until a fix is available. Avoid using the uisessionid parameter in affected components to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4818

Affected Products

Asset Management Essentials
Ibm Maximo Asset Management