CVE-2016-8924: XSS
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8924?
CVE-2016-8924 has a high severity rating due to the potential for remote session hijacking.
How do I fix CVE-2016-8924?
To mitigate CVE-2016-8924, apply the latest security updates provided by IBM for Maximo Asset Management.
Who is affected by CVE-2016-8924?
CVE-2016-8924 affects users of IBM Maximo Asset Management versions 7.1, 7.5, and 7.6.
What could an attacker do with CVE-2016-8924?
An attacker could exploit CVE-2016-8924 to hijack another user's session, gaining unauthorized access.
Is CVE-2016-8924 still a risk today?
Yes, if the affected versions of IBM Maximo Asset Management have not been updated, CVE-2016-8924 remains a significant security risk.