PT-2017-12985 · Ibm · Ibm Maximo Asset Management

Published

2017-09-12

·

Updated

2017-09-21

·

CVE-2017-1352

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management versions 7.5 through 7.6
Description The issue allows an authenticated user to inject commands into work orders. These commands could be executed by another user who downloads the affected file.
Recommendations For IBM Maximo Asset Management versions 7.5 through 7.6, consider restricting access to work order downloads to minimize the risk of exploitation until a patch is available.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1352

Affected Products

Ibm Maximo Asset Management