First published: Thu Jun 06 2019(Updated: )
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Control Desk | =7.6.0 | |
IBM Control Desk | =7.6.0.1 | |
IBM Maximo Asset Management | =7.6 | |
Ibm Maximo For Aviation | =7.6 | |
Ibm Maximo For Aviation | =7.6.1 | |
Ibm Maximo For Aviation | =7.6.2 | |
Ibm Maximo For Aviation | =7.6.2.1 | |
Ibm Maximo For Aviation | =7.6.3 | |
Ibm Maximo For Life Sciences | =7.6 | |
Ibm Maximo For Nuclear Power | =7.6.0 | |
Ibm Maximo For Oil And Gas | =7.6.0 | |
Ibm Maximo For Transportation | =7.6.1 | |
Ibm Maximo For Transportation | =7.6.2 | |
Ibm Maximo For Transportation | =7.6.2.1 | |
Ibm Maximo For Transportation | =7.6.2.2 | |
Ibm Maximo For Transportation | =7.6.2.3 | |
Ibm Maximo For Transportation | =7.6.2.4 | |
Ibm Maximo For Utilities | =7.6 | |
IBM SmartCloud Control Desk | ||
IBM Maximo Asset Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2028 is medium with a CVSS score of 6.5.
CVE-2018-2028 allows an authenticated user to replace a target page with a phishing site, potentially leading to the leakage of highly sensitive information in IBM Maximo Asset Management.
Yes, IBM Control Desk versions 7.6.0 and 7.6.0.1 are affected by CVE-2018-2028.
Yes, IBM has provided a fix for CVE-2018-2028. Please refer to the IBM support website for more details.
You can find more information about CVE-2018-2028 on the IBM X-Force Exchange website and the IBM support website.