IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/126538 | Third Party Advisory VDB Entry |
http://www.ibm.com/support/docview.wss?uid=swg22006650 | Vendor Advisory |
http://www.securityfocus.com/bid/100697 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-12 14:29
Updated : 2017-09-21 11:38
NVD link : CVE-2017-1352
Mitre link : CVE-2017-1352
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
ibm
- maximo_asset_management