CVE-2017-1352: Command Injection
Published Sep 12, 2017
·Updated
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
Affected Software
2 affected components
IBM Maximo Asset Management=7.5
IBM Maximo Asset Management=7.6
Event History
Sep 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1352?
CVE-2017-1352 is rated as medium severity due to the potential for command injection by authenticated users.
2
How do I fix CVE-2017-1352?
To fix CVE-2017-1352, update IBM Maximo Asset Management to the latest version that addresses the vulnerability.
3
Who is affected by CVE-2017-1352?
CVE-2017-1352 affects users of IBM Maximo Asset Management versions 7.5 and 7.6.
4
What impact can CVE-2017-1352 have on systems?
CVE-2017-1352 allows an authenticated user to inject and execute commands through work orders.
5
Is CVE-2017-1352 specific to IBM Maximo Asset Management?
Yes, CVE-2017-1352 specifically impacts IBM Maximo Asset Management software versions 7.5 and 7.6.