CVE-2016-5896: Infoleak
Published Feb 1, 2017
·Updated
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
Affected Software
6 affected components
IBM Maximo Asset Management=7.6
IBM Maximo For Aviation=7.6
IBM Maximo for Life Sciences=7.6
IBM Maximo for Nuclear Power=7.6
IBM Maximo for Oil and Gas=7.6
IBM Maximo for Transportation=7.6
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5896?
CVE-2016-5896 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2016-5896?
To mitigate CVE-2016-5896, it is recommended to upgrade to the latest version of IBM Maximo Asset Management or apply available patches.
3
Which versions of IBM Maximo are affected by CVE-2016-5896?
CVE-2016-5896 affects version 7.6 of IBM Maximo Asset Management and its various industry-specific modules.
4
What type of information is exposed by CVE-2016-5896?
CVE-2016-5896 may disclose sensitive information from a stack trace after an incorrect login attempt in the Cognos browser.
5
Is there a workaround for CVE-2016-5896?
A temporary workaround for CVE-2016-5896 is to limit access to the Cognos login interface until the system can be updated.