First published: Fri May 26 2017(Updated: )
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5 | |
IBM Maximo Asset Management | =7.6 | |
Ibm Maximo Asset Management Essentials | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1292 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To remediate CVE-2017-1292, it is recommended to follow IBM's official security updates and apply the necessary patches.
CVE-2017-1292 affects IBM Maximo Asset Management versions 7.5 and 7.6, as well as IBM Maximo Asset Management Essentials version 7.5.
CVE-2017-1292 can generate error messages that may reveal sensitive system information potentially useful for further attacks.
As a temporary measure, limiting access to error messages and improving logging security can help mitigate the risks associated with CVE-2017-1292.