First published: Tue Sep 12 2017(Updated: )
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5 | |
IBM Maximo Asset Management | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1352 is rated as medium severity due to the potential for command injection by authenticated users.
To fix CVE-2017-1352, update IBM Maximo Asset Management to the latest version that addresses the vulnerability.
CVE-2017-1352 affects users of IBM Maximo Asset Management versions 7.5 and 7.6.
CVE-2017-1352 allows an authenticated user to inject and execute commands through work orders.
Yes, CVE-2017-1352 specifically impacts IBM Maximo Asset Management software versions 7.5 and 7.6.