First published: Wed Jun 07 2017(Updated: )
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.1 | |
IBM Maximo Asset Management | =7.5 | |
IBM Maximo Asset Management | =7.6 | |
IBM Maximo Asset Management Essentials | =7.1 | |
IBM Maximo Asset Management Essentials | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9977 is considered a moderate severity vulnerability due to its potential for session hijacking.
To remediate CVE-2016-9977, ensure that session identifiers are invalidated properly upon logout or session expiration.
CVE-2016-9977 affects specific versions of IBM Maximo Asset Management, namely 7.1, 7.5, and 7.6.
Yes, CVE-2016-9977 can be exploited by remote attackers to hijack a user's session.
Users of IBM Maximo Asset Management versions 7.1, 7.5, and 7.6, as well as IBM Maximo Asset Management Essentials versions 7.1 and 7.5, are affected by CVE-2016-9977.