CVE-2017-1352
Summary
| CVE | CVE-2017-1352 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-12 21:29:00 UTC |
| Updated | 2017-09-21 18:38:00 UTC |
| Description | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Maximo Asset Management | 7.5 | All | All | All |
| Application | Ibm | Maximo Asset Management | 7.6 | All | All | All |
| Application | Ibm | Maximo Asset Management | 7.5 | All | All | All |
| Application | Ibm | Maximo Asset Management | 7.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| IBM Maximo Asset Management CVE-2017-1352 Remote Command Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Bulletin: IBM Maximo Asset Management could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file (CVE-2017-1352) | CONFIRM | www.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.