First published: Wed Feb 01 2017(Updated: )
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.6 | |
Ibm Maximo For Aviation | =7.6 | |
Ibm Maximo For Life Sciences | =7.6 | |
Ibm Maximo For Nuclear Power | =7.6 | |
Ibm Maximo For Oil And Gas | =7.6 | |
Ibm Maximo For Transportation | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5896 has a medium severity rating due to the potential exposure of sensitive information.
To mitigate CVE-2016-5896, it is recommended to upgrade to the latest version of IBM Maximo Asset Management or apply available patches.
CVE-2016-5896 affects version 7.6 of IBM Maximo Asset Management and its various industry-specific modules.
CVE-2016-5896 may disclose sensitive information from a stack trace after an incorrect login attempt in the Cognos browser.
A temporary workaround for CVE-2016-5896 is to limit access to the Cognos login interface until the system can be updated.