First published: Wed Nov 30 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.5.0.1 | |
IBM Maximo Asset Management | =7.5.0.2 | |
IBM Maximo Asset Management | =7.5.0.3 | |
IBM Maximo Asset Management | =7.5.0.4 | |
IBM Maximo Asset Management | =7.5.0.5 | |
IBM Maximo Asset Management | =7.5.0.6 | |
IBM Maximo Asset Management | =7.5.0.7 | |
IBM Maximo Asset Management | =7.5.0.8 | |
IBM Maximo Asset Management | =7.5.0.9 | |
IBM Maximo Asset Management | =7.6.0.0 | |
IBM Maximo Asset Management | =7.6.0.1 | |
IBM Maximo Asset Management | =7.6.0.2 | |
IBM Maximo Asset Management | =7.6.0.3 | |
IBM Maximo Asset Management | =7.6.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5905 is classified as a high severity vulnerability due to its potential for allowing cross-site scripting (XSS).
To mitigate CVE-2016-5905, upgrade IBM Maximo Asset Management to version 7.5.0.10 IF3 or 7.6.0.5 IF2 or later.
CVE-2016-5905 affects IBM Maximo Asset Management versions 7.5 below 7.5.0.10 IF3 and 7.6 below 7.6.0.5 IF2.
CVE-2016-5905 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML.
The impact of CVE-2016-5905 includes potential unauthorized access or manipulation of web content by malicious actors.