← Vulnerability feed

Vulnerability record · CVE-2017-1558 · published 13 December 2017

CVE-2017-1558: Ibm maximo asset management open redirect vulnerability

Ibm · Maximo Asset Management

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548.

6.1 CVSS 3.0 Medium EPSS 0.99% · top 38.9% CWE-601 · Open redirect
6.1CVSS 3.0 base score, v2 5.8
0.99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.ibm.com/support/docview.wss?uid=swg22010595 Issue TrackingVendor Advisory
http://www.securityfocus.com/bid/102211 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/131548 Issue TrackingVDB EntryVendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg22010595 Issue TrackingVendor Advisory
http://www.securityfocus.com/bid/102211 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/131548 Issue TrackingVDB EntryVendor Advisory

Track CVE-2017-1558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-32333Ibm maximo asset management improper access control vulnerabilityIBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.EPSS 0.55%9.8CVE-2021-20509Ibm maximo asset management injection vulnerabilityIBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…EPSS 1.7%9.8CVE-2020-4493Ibm maximo asset management vulnerabilityIBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP comman…EPSS 2.7%9.8CVE-2013-3323Ibm change and configuration management database improper privilege management vulnerabilityA Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …EPSS 2.9%9.8CVE-2017-1175Ibm maximo asset management sql injection vulnerabilityIBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which co…EPSS 1.9%8.8CVE-2023-47718Ibm maximo application suite cross-site request forgery vulnerabilityIBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker …EPSS 0.30%8.8CVE-2022-35281Ibm maximo application suite csv injection vulnerabilityIBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable t…EPSS 0.51%8.8CVE-2020-4521Ibm maximo asset management deserialization of untrusted data vulnerabilityIBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe …EPSS 6.5%

Source: NIST National Vulnerability Database (record CVE-2017-1558), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.