VulnerabilityModified
CVE-2017-1352
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file.
MEDIUM 5.5EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- ibm/maximo asset management
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22006650Vendor Advisory
- http://www.securityfocus.com/bid/100697Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126538Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg22006650Vendor Advisory
- http://www.securityfocus.com/bid/100697Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126538Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.