Medium severity5.5NVD Advisory· Published Sep 12, 2017· Updated May 13, 2026
CVE-2017-1352
CVE-2017-1352
Description
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
Affected products
3cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*
- IBM/Maximo Asset Managementv5Range: 7.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/docview.wssnvdVendor Advisory
- www.securityfocus.com/bid/100697nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/126538nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.