CVE-2018-1414: SQL Injection
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1414.
What is the severity level of CVE-2018-1414?
The severity level of CVE-2018-1414 is high.
What is the affected software of CVE-2018-1414?
The affected software of CVE-2018-1414 is IBM Maximo Asset Management 7.5 and 7.6.
How can a remote attacker exploit CVE-2018-1414?
A remote attacker can exploit CVE-2018-1414 by sending specially-crafted SQL statements to the vulnerable system.
Are there any references available for more information about CVE-2018-1414?
Yes, you can find more information about CVE-2018-1414 at the following references: (1) http://www.ibm.com/support/docview.wss?uid=swg22013797, (2) http://www.securityfocus.com/bid/103154, (3) https://exchange.xforce.ibmcloud.com/vulnerabilities/138820.