cbcvebase.
CVE-2019-4671
published 2020-09-15

CVE-2019-4671: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow…

medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmmaximo_asset_management
ibmmaximo_asset_management
ibmmaximo_asset_management>= 7.6.0 < 7.6.0.107.6.0.10
ibmmaximo_asset_management>= 7.6.1 < 7.6.1.27.6.1.2