CVE-2011-4817: Infoleak
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4817?
The severity of CVE-2011-4817 is considered low.
How do I fix CVE-2011-4817?
To fix CVE-2011-4817, apply the latest patches provided by IBM for the affected versions.
Which IBM products are affected by CVE-2011-4817?
CVE-2011-4817 affects IBM Maximo Asset Management, IBM Tivoli Asset Management for IT, and IBM Tivoli Service Request Manager.
What are the affected versions for CVE-2011-4817?
Affected versions of CVE-2011-4817 include IBM Maximo Asset Management versions 6.2, 7.1, 7.5 and similar versions for Essentials, Tivoli Asset Management for IT, and Tivoli Service Request Manager.
What vulnerabilities does CVE-2011-4817 exploit?
CVE-2011-4817 exploits a weakness in the About option on the Help menu of the affected IBM products.