Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Maximo Asset Management contains a vulnerability which could allow a user to log in with an expired password (CVE-2015-5017)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM Maximo Asset Management contains a vulnerability which could allow a user to log into the system with an expired password. This vulnerability could allow a local attacker to obtain sensitive information or compromise the integrity of the system. The vulnerability affects Maximo Asset Management, Maximo Asset Management Essentials, Maximo Industry Solutions (including Maximo for Energy Optimization, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_maximo_asset_management_contains_a_vulnerability_which_could_allow_a_user_to_log_in_with_an_expired_password_cve_2015_5017?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-5017 ,CVE-2015-4945 ,CVE-2015-7450 ,CVE-2015-7438 ,CVE-2015-7437 ,CVE-2015-4872 ,CVE-2015-4734 and CVE-2015-5006.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-28

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT