CVE-2018-1697: Infoleak
Published Dec 5, 2018
·Updated
IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
Affected Software
1 affected component
IBM Maximo Asset Management=7.6
Event History
Dec 5, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1697?
CVE-2018-1697 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-1697?
To mitigate CVE-2018-1697, users should apply the latest security updates provided by IBM for Maximo Asset Management 7.6.
3
Who is affected by CVE-2018-1697?
CVE-2018-1697 affects users of IBM Maximo Asset Management version 7.6.
4
What type of attack does CVE-2018-1697 allow?
CVE-2018-1697 allows authenticated users to enumerate usernames through specially crafted HTTP requests.
5
Are there any known exploits for CVE-2018-1697?
As of now, there are no publicly known exploits specifically targeting CVE-2018-1697.