cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 2 of 10
CVE-2022-40616P3HIGHCVSS 8.1v7.6.1.1v7.6.1.2+1 more2022-09-21
CVE-2022-40616 [HIGH] CWE-287 CVE-2022-40616: IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authenticatio IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access to. IBM X-Force ID: 236311.
nvd
CVE-2023-47718P3HIGHCVSS 8.8v7.6.1.32024-01-19
CVE-2023-47718 [HIGH] CWE-352 CVE-2023-47718: IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-si IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 271843.
nvd
CVE-2013-5395P3HIGHCVSS 7.5v7.1v7.1.1+24 more2013-10-01
CVE-2013-5395 [HIGH] CVE-2013-5395: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2019-4671P3MEDIUMCVSS 6.3≥ 7.6.0, < 7.6.0.10≥ 7.6.1, < 7.6.1.2+2 more2020-09-15
CVE-2019-4671 [MEDIUM] CWE-89 CVE-2019-4671: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.
nvd
CVE-2020-4529P3HIGHCVSS 7.4v7.6.0.0v7.6.1.0+2 more2020-06-08
CVE-2020-4529 [HIGH] CWE-918 CVE-2020-4529: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). Thi IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
nvd
CVE-2023-32335P3HIGHCVSS 7.5v7.6.1.32024-03-13
CVE-2023-32335 [HIGH] CWE-598 CVE-2023-32335: IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive inf IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.
nvd
CVE-2019-4650P3MEDIUMCVSS 6.3v7.6.1.12020-06-26
CVE-2019-4650 [MEDIUM] CWE-89 CVE-2019-4650: IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send spe IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.
nvd
CVE-2013-4017P3MEDIUMCVSS 6.5v7.1v7.1.1+9 more2013-10-01
CVE-2013-4017 [MEDIUM] CWE-89 CVE-2013-4017: SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attacke SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2021-29854P3HIGHCVSS 7.2v7.6.1.1v7.6.1.22022-05-03
CVE-2021-29854 [HIGH] CWE-116 CVE-2021-29854: IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by im IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable s
nvd
CVE-2011-4816P3MEDIUMCVSS 6.5v6.2v7.1+1 more2012-03-13
CVE-2011-4816 [MEDIUM] CWE-89 CVE-2011-4816: SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows
nvd
CVE-2013-4016P3MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+13 more2014-05-26
CVE-2013-4016 [MEDIUM] CWE-89 CVE-2013-4016: SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7 SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management
nvd
CVE-2015-4967P3MEDIUMCVSS 6.5v7.1v7.1.1+21 more2015-10-06
CVE-2015-4967 [MEDIUM] CWE-89 CVE-2015-4967: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0. SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT
nvd
CVE-2022-35281P3HIGHCVSS 8.8v7.6.1.1v7.6.1.2+2 more2023-01-09
CVE-2022-35281 [HIGH] CWE-1236 CVE-2022-35281: IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and the IBM Maximo Manage 8.3, 8.4 application in IBM Maximo Application Suite are vulnerable to CSV injection. IBM X-Force ID: 2306335.
nvd
CVE-2020-4409P3HIGHCVSS 8.2fixed in 7.6.1.2v7.6.0+1 more2020-09-16
CVE-2020-4409 [HIGH] CWE-601 CVE-2020-4409: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attack IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obt
nvd
CVE-2021-38935P3HIGHCVSS 7.5v7.6.1.22022-02-18
CVE-2021-38935 [HIGH] CWE-521 CVE-2021-38935: IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by defa IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
nvd
CVE-2012-0728P3MEDIUMCVSS 6.5v7.1.0.0v7.5.0.02012-09-10
CVE-2012-0728 [MEDIUM] CWE-89 CVE-2012-0728: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Co SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-0727P3MEDIUMCVSS 6.5v7.5.0.02012-09-10
CVE-2012-0727 [MEDIUM] CWE-89 CVE-2012-0727: SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-0747P3MEDIUMCVSS 6.5v6.2.0.0v7.1.0.0+1 more2012-09-10
CVE-2012-0747 [MEDIUM] CWE-89 CVE-2012-0747: SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Co SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2024-45077P3MEDIUMCVSS 6.5v7.6.1.32025-01-24
CVE-2024-45077 [MEDIUM] CWE-98 CVE-2024-45077: IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which a IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.
nvd
CVE-2015-7448P3MEDIUMCVSS 5.4v7.1v7.1.1+25 more2016-03-12
CVE-2015-7448 [MEDIUM] CWE-89 CVE-2015-7448: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0. SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Managemen
nvd