CVE-2018-2028: Medium severity ibm smartcloud control desk vulnerability
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2028?
The severity of CVE-2018-2028 is medium with a CVSS score of 6.5.
How does CVE-2018-2028 affect IBM Maximo Asset Management?
CVE-2018-2028 allows an authenticated user to replace a target page with a phishing site, potentially leading to the leakage of highly sensitive information in IBM Maximo Asset Management.
Is IBM Control Desk affected by CVE-2018-2028?
Yes, IBM Control Desk versions 7.6.0 and 7.6.0.1 are affected by CVE-2018-2028.
Is there a fix available for CVE-2018-2028?
Yes, IBM has provided a fix for CVE-2018-2028. Please refer to the IBM support website for more details.
Where can I find more information about CVE-2018-2028?
You can find more information about CVE-2018-2028 on the IBM X-Force Exchange website and the IBM support website.