CVE-2017-1176
https://notcve.org/view.php?id=CVE-2017-1176
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 http://www.securityfocus.com/bid/99371 https://exchange.xforce.ibmcloud.com/vulnerabilities/123299 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9984
https://notcve.org/view.php?id=CVE-2016-9984
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276. Maximo Asset Management versiones 7.5 y 7.6 de IBM, podría permitir a un atacante identificado remoto ejecutar comandos arbitrarios en el sistema como administrador. ID de IBM X-Force: 120276. • http://www.ibm.com/support/docview.wss?uid=swg21998608 https://exchange.xforce.ibmcloud.com/vulnerabilities/120276 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-8987
https://notcve.org/view.php?id=CVE-2016-8987
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un usuario autenticado visualizar un conjunto de elementos inapropiados que no deberían tener acceso para visualización. • http://www.ibm.com/support/docview.wss?uid=swg21996255 http://www.securityfocus.com/bid/97369 https://exchange.xforce.ibmcloud.com/vulnerabilities/119039 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9977
https://notcve.org/view.php?id=CVE-2016-9977
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un atacante remoto secuestrar la sesión de usuario, causado por un fallo para invalidar un identificador de sesión existente. Un atacante podría explotar esta vulnerabilidad para conseguir acceso a la sesión de otro usuario. • http://www.ibm.com/support/docview.wss?uid=swg22003981 http://www.securityfocus.com/bid/98786 https://exchange.xforce.ibmcloud.com/vulnerabilities/120253 • CWE-20: Improper Input Validation •
CVE-2017-1291
https://notcve.org/view.php?id=CVE-2017-1291
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152. Maximo Asset Management versiones 7.5 y 7.6 de IBM, es vulnerable a ataques de división de respuestas HTTP. • http://www.ibm.com/support/docview.wss?uid=swg22003413 https://exchange.xforce.ibmcloud.com/vulnerabilities/125152 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •