PT-2017-10404 · Ibm · Ibm Maximo Asset Management

Published

2017-06-07

·

Updated

2017-06-12

·

CVE-2016-9977

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management versions 7.1 through 7.6
Description The issue is caused by the failure to invalidate an existing session identifier, allowing a remote attacker to hijack a user's session. This could enable the attacker to gain access to another user's session.
Recommendations For versions 7.1 through 7.6, update the software to invalidate existing session identifiers after a user logs out to prevent session hijacking.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9977

Affected Products

Ibm Maximo Asset Management