CVE-2017-1352
 
Severity Score
5.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado inyecte comandos en órdenes de trabajo que podrían ser ejecutadas por otro usuario que descargue el archivo afectado. IBM X-Force ID: 126538.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-11-30 CVE Reserved
- 2017-09-12 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100697 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/126538 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/docview.wss?uid=swg22006650 | 2017-09-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Maximo Asset Management Search vendor "Ibm" for product "Maximo Asset Management" | 7.5 Search vendor "Ibm" for product "Maximo Asset Management" and version "7.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Maximo Asset Management Search vendor "Ibm" for product "Maximo Asset Management" | 7.6 Search vendor "Ibm" for product "Maximo Asset Management" and version "7.6" | - |
Affected
|