Vulnerability Bulletins

IBM Security Bulletin: COGNOS DIRECT INTEGRATION ACCESS REMAINS OPEN AFTER CLOSING MAXIMO SESSION (CVE-2014-6102)

   
Affected software IBM
 
IBM Maximo Asset Management could allow a user to access Cognos BI even after the Maximo session is closed. CVE(s): CVE-2014-6102 Affected product(s) and affected version(s): 1. Maximo Asset Management 7.5, 7.1 2. Maximo Asset Management Essentials 7.5, 7.1 3. Maximo for Government 7.5, 7.1 4. Maximo for Nuclear Power 7.5, 7.1 5. Maximo for Transportation 7.5, 7.1 6. Maximo for Life Sciences 7.5, 7.1 7. Maximo for Oil and Gas 7.5, 7.1 8. Maximo for Utilities 7.5, 7.1 9. SmartCloud Control

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_cognos_direct_integration_access_remains_open_after_closing_maximo_session_cve_2014_6102?lang=en_us