First published: Wed Jul 05 2017(Updated: )
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.1 | |
IBM Maximo Asset Management | =7.1.1 | |
IBM Maximo Asset Management | =7.5 | |
IBM Maximo Asset Management | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1175 has a medium severity rating due to its potential for unauthorized database manipulation.
To fix CVE-2017-1175, it is recommended to apply the latest security updates provided by IBM for Maximo Asset Management.
CVE-2017-1175 affects IBM Maximo Asset Management versions 7.1, 7.5, and 7.6.
CVE-2017-1175 is an SQL injection vulnerability allowing attackers to interact with the back-end database.
Yes, CVE-2017-1175 can be exploited remotely by sending specially-crafted SQL statements.