CVE-2017-1124

Severity
2.9LOW
EPSS
0.0%
top 86.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 17

Description

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 1.4 | Impact: 1.4

Affected Packages2 packages

NVDibm/maximo_asset_management32 versions+31
CVEListV5ibm_corporation/maximo_asset_management37 versions+36

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rm2x-c3c3-pwmx: IBM Maximo Asset Management 72022-05-17
CVEList
CVE-2017-1124: IBM Maximo Asset Management 72017-03-07

💬Community

12
Bugzilla
CVE-2017-5060 chromium-browser: url spoofing in omnibox2017-04-20
Bugzilla
CVE-2017-5061 chromium-browser: url spoofing in omnibox2017-04-20
Bugzilla
CVE-2017-5063 chromium-browser: heap overflow in skia2017-04-20
Bugzilla
CVE-2017-5069 chromium-browser: cross-origin bypass in blink2017-04-20
Bugzilla
CVE-2017-5062 chromium-browser: use after free in chrome apps2017-04-20
CVE-2017-1124 (LOW CVSS 2.9) | IBM Maximo Asset Management 7.1 | cvebase.io