Ibm Maximo Anywhere vulnerabilities
11 known vulnerabilities affecting ibm/maximo_anywhere.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7LOW4
Vulnerabilities
Page 1 of 1
CVE-2019-4291MEDIUMCVSS 6.5v7.6.4.02022-02-16
CVE-2019-4291 [MEDIUM] CWE-326 CVE-2019-4291: IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the l
IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697.
cvelistv5nvd
CVE-2019-4351MEDIUMCVSS 4.6v7.6.4.02022-02-16
CVE-2019-4351 [MEDIUM] CVE-2019-4351: IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physica
IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: 161493.
cvelistv5nvd
CVE-2019-4352LOWCVSS 2.4v7.6.4.02022-02-16
CVE-2019-4352 [LOW] CVE-2019-4352: IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM
IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.
cvelistv5nvd
CVE-2019-4349LOWCVSS 3.5v7.6.2.0v7.6.2.1+2 more2020-11-03
CVE-2019-4349 [LOW] CWE-200 CVE-2019-4349: IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprec
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the service. IBM X-Force ID: 161486
cvelistv5nvd
CVE-2019-4266LOWCVSS 2.4v7.6.2.0v7.6.2.1+2 more2020-05-06
CVE-2019-4266 [LOW] CWE-269 CVE-2019-4266: IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160199.
cvelistv5nvd
CVE-2019-4288MEDIUMCVSS 4.3v7.6.2.0v7.6.2.1+2 more2020-04-29
CVE-2019-4288 [MEDIUM] CVE-2019-4288: IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user info
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631.
cvelistv5nvd
CVE-2019-4286MEDIUMCVSS 4.3v7.6.2.0v7.6.2.1+2 more2020-04-29
CVE-2019-4286 [MEDIUM] CWE-532 CVE-2019-4286: IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user info
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.
cvelistv5nvd
CVE-2019-4429MEDIUMCVSS 5.4v7.6.0.0v7.6.1.02020-02-19
CVE-2019-4429 [MEDIUM] CWE-79 CVE-2019-4429: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
nvd
CVE-2019-4265LOWCVSS 2.4v7.6.0.0v7.6.1.0+3 more2019-10-10
CVE-2019-4265 [LOW] CWE-922 CVE-2019-4265: IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could r
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.
cvelistv5nvd
CVE-2017-1604MEDIUMCVSS 5.4v7.5.1.2v7.5.2.0+8 more2018-02-21
CVE-2017-1604 [MEDIUM] CWE-79 CVE-2017-1604: IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132851.
cvelistv5nvd
CVE-2015-4945MEDIUMCVSS 5.0v7.5.1.0v7.5.1.1+1 more2015-07-26
CVE-2015-4945 [MEDIUM] CWE-200 CVE-2015-4945: Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android a
Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application.
nvd