IBM Maximo Asset Management product defects and Multiple Security Vulnerabilities

Source: Internet
Author: User

Release date:
Updated on:

Affected Systems:
IBM Maximo Asset Management 7.x
IBM Maximo Asset Management 6.x
IBM Maximo Asset Management essenessen7.x
IBM Maximo Asset Management Essentials 6.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-1394, CVE-2011-1395, CVE-2011-1396, CVE-2011-1397, CVE-2011-4816, CVE-2011-4817, CVE-2011-4818, CVE-2011-4819

The IBM Maximo Asset Management software provides comprehensive Asset lifecycle and maintenance Management for all Asset types.

Multiple vulnerabilities exist in IBM Maximo Asset Management and IBM Maximo Asset Management essensoftware, which can be exploited by malicious users to leak sensitive information and execute SQL injection attacks, or execute cross-site scripting to execute attacks and cause DOS.

1) The disabled user name is displayed in the "about" option in the "help" menu.

2) If the input to the script through the "uisessionid" parameter is not correctly verified, it is used to redirect the user.

3) if the input to the script through the "controlid" parameter to the imicon. jsp and "reportType" parameter is not correctly verified, it is returned to the user.

4) if the input to the ui/and maximo. jsp through the "uisesionid" parameter is not correctly verified, it is returned to the user.

5) some inputs in Start Center Layout and Configuration are returned to the user if they are not correctly verified.

6) applications allow users to perform certain operations through HTTP requests without verifying the requests.

7) handle errors in multiple UI sessions in an HTTP session.

8) some inputs passed to the KPI component are used for SQL queries if they are not properly filtered.

<* Source: IBM (ncsupp@ca.ibm.com)

Link: http://secunia.com/advisories/48299/
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:

IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:

Http://www.ers.ibm.com/

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.