CVE-2017-1175: SQL Injection
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1175?
CVE-2017-1175 has a medium severity rating due to its potential for unauthorized database manipulation.
How do I fix CVE-2017-1175?
To fix CVE-2017-1175, it is recommended to apply the latest security updates provided by IBM for Maximo Asset Management.
What versions are affected by CVE-2017-1175?
CVE-2017-1175 affects IBM Maximo Asset Management versions 7.1, 7.5, and 7.6.
What type of vulnerability is CVE-2017-1175?
CVE-2017-1175 is an SQL injection vulnerability allowing attackers to interact with the back-end database.
Can CVE-2017-1175 be exploited remotely?
Yes, CVE-2017-1175 can be exploited remotely by sending specially-crafted SQL statements.