CVE-2016-8924
CVE-2016-8924
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Apr 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
Affected products
IBM Corporation · Maximo Asset ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →