CVE-2018-1528: Infoleak
Published Aug 6, 2018
·Updated
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
Affected Software
18 affected components
IBM Maximo Asset Management>=7.6.0.0<=7.6.3.0
IBM Maximo For Aviation=7.6.0.0
IBM Maximo For Aviation=7.6.1.0
IBM Maximo For Aviation=7.6.2.0
IBM Maximo For Aviation=7.6.2.1
IBM Maximo For Aviation=7.6.3.0
IBM Maximo for Life Sciences=7.6.0.0
IBM Maximo for Nuclear Power=7.6.0.0
IBM Maximo for Oil and Gas=7.6.0.0
IBM Maximo for Transportation=7.6.1.0
IBM Maximo for Transportation=7.6.2.0
IBM Maximo for Transportation=7.6.2.1
IBM Maximo for Transportation=7.6.2.2
IBM Maximo for Transportation=7.6.2.3
IBM Maximo for Transportation=7.6.2.4
IBM Maximo for Utilities=7.6.0.0
IBM SmartCloud Control Desk=7.6.0.0
IBM SmartCloud Control Desk=7.6.0.1
Remediation
Patch Available
Event History
Aug 6, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1528?
The severity of CVE-2018-1528 is medium.
2
Who is affected by CVE-2018-1528?
IBM Maximo Asset Management versions 7.6 through 7.6.3 are affected by CVE-2018-1528.
3
How can an authenticated user obtain sensitive information from the WhoAmI API in IBM Maximo Asset Management?
An authenticated user can obtain sensitive information from the WhoAmI API in IBM Maximo Asset Management by exploiting CVE-2018-1528.
4
Are there any available fixes or patches for CVE-2018-1528?
Yes, IBM has provided a fix for CVE-2018-1528. It is recommended to upgrade to a fixed version of IBM Maximo Asset Management.
5
Where can I find more information about CVE-2018-1528?
More information about CVE-2018-1528 can be found on the IBM X-Force ID and the IBM support website.