CVE-2016-9976: High severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9976?
CVE-2016-9976 is rated as a high severity vulnerability due to its potential for remote code execution.
How can I mitigate CVE-2016-9976?
To mitigate CVE-2016-9976, users should apply the latest security patches provided by IBM for affected versions of Maximo Asset Management.
Which versions of IBM Maximo Asset Management are affected by CVE-2016-9976?
CVE-2016-9976 affects IBM Maximo Asset Management versions 7.1, 7.5, and 7.6, as well as their Essentials counterparts.
What type of attack is associated with CVE-2016-9976?
CVE-2016-9976 allows for remote file inclusion attacks that can lead to arbitrary code execution on the server.
Is there an exploit available for CVE-2016-9976?
Yes, there are reported exploits in the wild that could take advantage of the CVE-2016-9976 vulnerability.