CVE-2018-1698: Infoleak
Published Sep 13, 2018
·Updated
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.
Affected Software
1 affected component
IBM Maximo Asset Management>=7.6<=7.6.3
Remediation
Patch Available
Event History
Sep 13, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1698?
CVE-2018-1698 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-1698?
To fix CVE-2018-1698, upgrade IBM Maximo Asset Management to version 7.6.4 or later.
3
What type of information can be leaked due to CVE-2018-1698?
CVE-2018-1698 can allow an unauthenticated attacker to obtain sensitive information from error messages.
4
Which versions of IBM Maximo Asset Management are affected by CVE-2018-1698?
IBM Maximo Asset Management versions 7.6 through 7.6.3 are affected by CVE-2018-1698.
5
Is CVE-2018-1698 a local or remote vulnerability?
CVE-2018-1698 is a remote vulnerability that can be exploited by unauthenticated attackers.