CVE-2018-1528

Severity
4.3MEDIUM
EPSS
0.2%
top 62.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 13

Description

IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDibm/maximo_asset_management7.6.0.07.6.3.0
CVEListV5ibm/maximo_asset_management10 versions+9
NVDibm/maximo8 versions+7
NVDibm/smartcloud_control_desk7.6.0.0, 7.6.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vmj5-3j96-8g82: IBM Maximo Asset Management 72022-05-13
CVEList
CVE-2018-1528: IBM Maximo Asset Management 72018-08-06

💥Exploits & PoCs

1
Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion2018-06-11