CVE-2016-9977: Input Validation
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9977?
CVE-2016-9977 is considered a moderate severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2016-9977?
To remediate CVE-2016-9977, ensure that session identifiers are invalidated properly upon logout or session expiration.
Is CVE-2016-9977 present in all versions of IBM Maximo Asset Management?
CVE-2016-9977 affects specific versions of IBM Maximo Asset Management, namely 7.1, 7.5, and 7.6.
Can CVE-2016-9977 be exploited remotely?
Yes, CVE-2016-9977 can be exploited by remote attackers to hijack a user's session.
Who is affected by CVE-2016-9977?
Users of IBM Maximo Asset Management versions 7.1, 7.5, and 7.6, as well as IBM Maximo Asset Management Essentials versions 7.1 and 7.5, are affected by CVE-2016-9977.