First published: Sun Jul 17 2016(Updated: )
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.5.0.1 | |
IBM Maximo Asset Management | =7.5.0.2 | |
IBM Maximo Asset Management | =7.5.0.3 | |
IBM Maximo Asset Management | =7.5.0.4 | |
IBM Maximo Asset Management | =7.5.0.5 | |
IBM Maximo Asset Management | =7.5.0.6 | |
IBM Maximo Asset Management | =7.5.0.7 | |
IBM Maximo Asset Management | =7.5.0.8 | |
IBM Maximo Asset Management | =7.5.0.9 | |
IBM Maximo Asset Management | =7.5.0.10 | |
IBM Maximo Asset Management | =7.6.0.0 | |
IBM Maximo Asset Management | =7.6.0.1 | |
IBM Maximo Asset Management | =7.6.0.2 | |
IBM Maximo Asset Management | =7.6.0.3 | |
IBM Maximo Asset Management | =7.6.0.4 | |
IBM Maximo Asset Management | =7.6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0393 is considered moderate due to the potential exposure of sensitive URL information.
To fix CVE-2016-0393, update to IBM Maximo Asset Management version 7.5.0.10-TIV-MBS-IFIX002 or 7.6.0.5-TIV-MAMMT-FP001 or later.
Affected versions for CVE-2016-0393 include IBM Maximo Asset Management 7.5 before 7.5.0.10 and 7.6 before 7.6.0.5.
Yes, CVE-2016-0393 can be exploited remotely by attackers to access sensitive information.
CVE-2016-0393 exposes sensitive URL information through log files.