CVE-2016-0393: Infoleak
Published Jul 17, 2016
·Updated
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
Affected Software
17 affected components
IBM Maximo Asset Management=7.5.0.0
IBM Maximo Asset Management=7.5.0.1
IBM Maximo Asset Management=7.5.0.2
IBM Maximo Asset Management=7.5.0.3
IBM Maximo Asset Management=7.5.0.4
IBM Maximo Asset Management=7.5.0.5
IBM Maximo Asset Management=7.5.0.6
IBM Maximo Asset Management=7.5.0.7
IBM Maximo Asset Management=7.5.0.8
IBM Maximo Asset Management=7.5.0.9
IBM Maximo Asset Management=7.5.0.10
IBM Maximo Asset Management=7.6.0.0
IBM Maximo Asset Management=7.6.0.1
IBM Maximo Asset Management=7.6.0.2
IBM Maximo Asset Management=7.6.0.3
IBM Maximo Asset Management=7.6.0.4
IBM Maximo Asset Management=7.6.0.5
Event History
Jul 17, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0393?
The severity of CVE-2016-0393 is considered moderate due to the potential exposure of sensitive URL information.
2
How do I fix CVE-2016-0393?
To fix CVE-2016-0393, update to IBM Maximo Asset Management version 7.5.0.10-TIV-MBS-IFIX002 or 7.6.0.5-TIV-MAMMT-FP001 or later.
3
What are the affected versions for CVE-2016-0393?
Affected versions for CVE-2016-0393 include IBM Maximo Asset Management 7.5 before 7.5.0.10 and 7.6 before 7.6.0.5.
4
Can CVE-2016-0393 be exploited remotely?
Yes, CVE-2016-0393 can be exploited remotely by attackers to access sensitive information.
5
What type of information is exposed by CVE-2016-0393?
CVE-2016-0393 exposes sensitive URL information through log files.