First published: Tue Jul 31 2018(Updated: )
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | >=7.6.0.0<=7.6.3.0 | |
Ibm Maximo For Aviation | =7.6.0.0 | |
Ibm Maximo For Aviation | =7.6.1.0 | |
Ibm Maximo For Aviation | =7.6.2.0 | |
Ibm Maximo For Aviation | =7.6.2.1 | |
Ibm Maximo For Aviation | =7.6.3.0 | |
Ibm Maximo For Life Sciences | =7.6.0.0 | |
Ibm Maximo For Nuclear Power | =7.6.0.0 | |
Ibm Maximo For Oil And Gas | =7.6.0.0 | |
Ibm Maximo For Transportation | =7.6.1.0 | |
Ibm Maximo For Transportation | =7.6.2.0 | |
Ibm Maximo For Transportation | =7.6.2.1 | |
Ibm Maximo For Transportation | =7.6.2.2 | |
Ibm Maximo For Transportation | =7.6.2.3 | |
Ibm Maximo For Transportation | =7.6.2.4 | |
Ibm Maximo For Utilities | =7.6.0.0 | |
IBM SmartCloud Control Desk | =7.6.0.0 | |
IBM SmartCloud Control Desk | =7.6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1528 is medium.
IBM Maximo Asset Management versions 7.6 through 7.6.3 are affected by CVE-2018-1528.
An authenticated user can obtain sensitive information from the WhoAmI API in IBM Maximo Asset Management by exploiting CVE-2018-1528.
Yes, IBM has provided a fix for CVE-2018-1528. It is recommended to upgrade to a fixed version of IBM Maximo Asset Management.
More information about CVE-2018-1528 can be found on the IBM X-Force ID and the IBM support website.