{"api_version":"1","generated_at":"2026-07-23T04:33:19+00:00","cve":"CVE-2017-1352","urls":{"html":"https://cve.report/CVE-2017-1352","api":"https://cve.report/api/cve/CVE-2017-1352.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-1352","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-1352"},"summary":{"title":"CVE-2017-1352","description":"IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2017-09-12 21:29:00","updated_at":"2017-09-21 18:38:00"},"problem_types":["CWE-77"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/126538","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/126538","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100697","name":"100697","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"IBM Maximo Asset Management CVE-2017-1352 Remote Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ibm.com/support/docview.wss?uid=swg22006650","name":"http://www.ibm.com/support/docview.wss?uid=swg22006650","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: IBM Maximo Asset Management could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file (CVE-2017-1352)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-1352","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1352","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"1352","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"maximo_asset_management","cpe6":"7.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1352","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"maximo_asset_management","cpe6":"7.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1352","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"maximo_asset_management","cpe6":"7.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1352","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"maximo_asset_management","cpe6":"7.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2017-09-06T00:00:00","ID":"CVE-2017-1352","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Maximo Asset Management","version":{"version_data":[{"version_value":"7.5"},{"version_value":"7.6"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Privileges"}]}]},"references":{"reference_data":[{"name":"http://www.ibm.com/support/docview.wss?uid=swg22006650","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg22006650"},{"name":"100697","refsource":"BID","url":"http://www.securityfocus.com/bid/100697"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/126538","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/126538"}]}},"nvd":{"publishedDate":"2017-09-12 21:29:00","lastModifiedDate":"2017-09-21 18:38:00","problem_types":["CWE-77"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.1,"impactScore":3.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"1352","Ordinal":"97425","Title":"CVE-2017-1352","CVE":"CVE-2017-1352","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"1352","Ordinal":"1","NoteData":"IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"1352","Ordinal":"2","NoteData":"2017-09-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"1352","Ordinal":"3","NoteData":"2017-09-13","Type":"Other","Title":"Modified"}]}}}