Wednesday, September 2, 2015

IBM Security Bulletin: IBM Maximo Asset Management could allow a local attacker to obtain information due to the autocomplete feature on password input fields (CVE-2015-1933)

The autocomplete attribute of the password field on the Maximo Asset Management Login page is not set to false. This vulnerability could allow a local attacker to obtain account access. The vulnerability affects Maximo Asset Management, Maximo Asset Management...

from IBM Product Security Incident Response Team http://ift.tt/1O8Oaem

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.