CVE-2018-1698Sensitive Information Exposure in IBM Maximo Asset Management

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 58.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 13
Latest updateMay 13

Description

IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/maximo_asset_management7.67.6.3
CVEListV5ibm/maximo_asset_management10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w3j5-w5gc-px97: IBM Maximo Asset Management 72022-05-13
CVEList
CVE-2018-1698: IBM Maximo Asset Management 72018-09-13
CVE-2018-1698 — Sensitive Information Exposure in IBM | cvebase