Release date:
Updated on:
Affected Systems:
IBM Maximo Asset Management 7.x
IBM Maximo Asset Management 6.x
IBM Maximo Asset Management essenessen7.x
IBM Maximo Asset Management Essentials 6.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-1394, CVE-2011-1395, CVE-2011-1396, CVE-2011-1397, CVE-2011-4816, CVE-2011-4817, CVE-2011-4818, CVE-2011-4819
The IBM Maximo Asset Management software provides comprehensive Asset lifecycle and maintenance Management for all Asset types.
Multiple vulnerabilities exist in IBM Maximo Asset Management and IBM Maximo Asset Management essensoftware, which can be exploited by malicious users to leak sensitive information and execute SQL injection attacks, or execute cross-site scripting to execute attacks and cause DOS.
1) The disabled user name is displayed in the "about" option in the "help" menu.
2) If the input to the script through the "uisessionid" parameter is not correctly verified, it is used to redirect the user.
3) if the input to the script through the "controlid" parameter to the imicon. jsp and "reportType" parameter is not correctly verified, it is returned to the user.
4) if the input to the ui/and maximo. jsp through the "uisesionid" parameter is not correctly verified, it is returned to the user.
5) some inputs in Start Center Layout and Configuration are returned to the user if they are not correctly verified.
6) applications allow users to perform certain operations through HTTP requests without verifying the requests.
7) handle errors in multiple UI sessions in an HTTP session.
8) some inputs passed to the KPI component are used for SQL queries if they are not properly filtered.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://secunia.com/advisories/48299/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/