Vulnerability Bulletins

IBM Security Bulletin: IBM Maximo Asset Management contains a misconfiguration that could allow a remote attacker to gain elevated privileges on the system (CVE-2015-1927)

   
Affected software IBM
 
IBM Maximo Asset Management configuration files set the attribute serveServletsByClassnameEnabled to true. This vulnerability could allow a remote attacker to gain elevated privileges on the system. The vulnerability affects Maximo Asset Management, Maximo Asset Management Essentials, Maximo Industry Solutions (including Maximo for Energy Optimization, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_maximo_asset_management_contains_a_misconfiguration_that_could_allow_a_remote_attacker_to_gain_elevated_privileges_on_the_system_cve_2015_1927?lang=en_us