CVE-2017-1291: IBM Maximo Asset Management

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 125152.

Affected products

  • IBM Maximo Asset Management: version 7.5 only; version 7.6 only
  • IBM Maximo Asset Management Essentials: version 7.5 only

Published 2017-05-26. Last modified 2026-06-17.