CVE-2017-1352: IBM Maximo Asset Management

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.

Affected products

  • IBM Maximo Asset Management: version 7.5 only; version 7.6 only

Published 2017-09-12. Last modified 2026-06-17.