CVE-2015-1951: Infoleak
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1951?
CVE-2015-1951 is classified as a medium severity vulnerability.
How do I fix CVE-2015-1951?
To fix CVE-2015-1951, you should apply the latest security patches provided by IBM for your version of Maximo Asset Management.
What versions of IBM Maximo Asset Management are affected by CVE-2015-1951?
CVE-2015-1951 affects IBM Maximo Asset Management versions 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005.
What kind of attack can exploit CVE-2015-1951?
CVE-2015-1951 can be exploited by physically proximate attackers to obtain sensitive local-cache information from an unattended workstation.
Does CVE-2015-1951 involve HTTPS response caching issues?
Yes, CVE-2015-1951 specifically involves the inability to prevent caching of HTTPS responses.