First published: Thu Feb 22 2018(Updated: )
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.5.0.0 | |
IBM Maximo Asset Management | =7.6.0.0 | |
Ibm Maximo Asset Management Essentials | =7.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1414.
The severity level of CVE-2018-1414 is high.
The affected software of CVE-2018-1414 is IBM Maximo Asset Management 7.5 and 7.6.
A remote attacker can exploit CVE-2018-1414 by sending specially-crafted SQL statements to the vulnerable system.
Yes, you can find more information about CVE-2018-1414 at the following references: (1) http://www.ibm.com/support/docview.wss?uid=swg22013797, (2) http://www.securityfocus.com/bid/103154, (3) https://exchange.xforce.ibmcloud.com/vulnerabilities/138820.