Ibm Maximo Asset Management vulnerabilities
185 known vulnerabilities affecting ibm/maximo_asset_management.
Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26
Vulnerabilities
Page 1 of 10
CVE-2020-4463P1HIGHCVSS 8.2ExploitedPoCv7.6.0.1v7.6.0.22020-07-29
CVE-2020-4463 [HIGH] CWE-611 CVE-2020-4463: IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (X
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
nvd
CVE-2015-0104P2HIGHCVSS 8.8PoCv7.1v7.1.1+6 more2017-04-24
CVE-2015-0104 [HIGH] CWE-284 CVE-2015-0104: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspeci
nvd
CVE-2015-0107P3MEDIUMCVSS 6.5PoCv7.1v7.1.1+6 more2017-04-24
CVE-2015-0107 [MEDIUM] CWE-22 CVE-2015-0107: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attac
nvd
CVE-2020-4521P2HIGHCVSS 8.8≥ 7.6.0, < 7.6.0.10≥ 7.6.1, < 7.6.1.2+2 more2020-09-15
CVE-2020-4521 [HIGH] CWE-502 CVE-2020-4521: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute a
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396.
nvd
CVE-2017-1175P3CRITICALCVSS 9.8v7.1v7.1.1+2 more2017-07-05
CVE-2017-1175 [CRITICAL] CWE-89 CVE-2017-1175: IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker coul
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
nvd
CVE-2021-20509P3CRITICALCVSS 9.8fixed in 7.6.1.2v7.6.0+1 more2021-08-12
CVE-2021-20509 [CRITICAL] CWE-74 CVE-2021-20509: IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote att
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.
nvd
CVE-2017-1499P3HIGHCVSS 8.8v7.5.0.0v7.6.0.0+2 more2018-02-14
CVE-2017-1499 [HIGH] CWE-434 CVE-2017-1499: IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, wh
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.
nvd
CVE-2018-1699P3HIGHCVSS 8.8≥ 7.6, ≤ 7.6.3v7.6+9 more2018-08-24
CVE-2018-1699 [HIGH] CWE-89 CVE-2018-1699: IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker coul
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145968.
nvd
CVE-2013-3323P3CRITICALCVSS 9.8v6.2v7.1+1 more2020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2020-4493P3CRITICALCVSS 9.8≥ 7.6.0.0, < 7.6.0.10≥ 7.6.1.0, < 7.6.1.2+2 more2020-10-05
CVE-2020-4493 [CRITICAL] CVE-2020-4493: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and iss
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995.
nvd
CVE-2018-1414P3HIGHCVSS 8.8v7.5.0.0v7.6.0.0+2 more2018-02-22
CVE-2018-1414 [HIGH] CWE-89 CVE-2018-1414: IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
nvd
CVE-2016-9984P3HIGHCVSS 8.8v7.5v7.62017-06-13
CVE-2016-9984 [HIGH] CWE-264 CVE-2016-9984: IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbit
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
nvd
CVE-2018-1524P3HIGHCVSS 8.8≥ 7.6.0.0, ≤ 7.6.3.02018-08-03
CVE-2018-1524 [HIGH] CVE-2018-1524: IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a r
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
nvd
CVE-2016-9977P3HIGHCVSS 8.8v7.1v7.5+2 more2017-06-07
CVE-2016-9977 [HIGH] CWE-20 CVE-2016-9977: IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's sessi
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
nvd
CVE-2024-45652P3HIGHCVSS 7.5v7.6.1.32025-01-19
CVE-2024-45652 [HIGH] CWE-22 CVE-2024-45652: IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the syste
IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2023-32333P3CRITICALCVSS 9.8v7.6.1.32024-02-02
CVE-2023-32333 [CRITICAL] CWE-284 CVE-2023-32333: IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.
nvd
CVE-2016-9976P3HIGHCVSS 8.4v7.1v7.5+1 more2017-05-03
CVE-2016-9976 [HIGH] CWE-284 CVE-2016-9976: IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary fil
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
nvd
CVE-2024-27266P3HIGHCVSS 8.2v7.6.1.32024-03-14
CVE-2024-27266 [HIGH] CWE-611 CVE-2024-27266: IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.
nvd
CVE-2019-4430P3HIGHCVSS 7.5v7.62019-07-17
CVE-2019-4430 [HIGH] CWE-22 CVE-2019-4430: IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system.
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
nvd
CVE-2019-4364P3HIGHCVSS 8.0v7.62019-06-19
CVE-2019-4364 [HIGH] CWE-1236 CVE-2019-4364: IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authentic
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
nvd
1 / 10Next →