Ibm Maximo Asset Management vulnerabilities
185 known vulnerabilities affecting ibm/maximo_asset_management.
Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26
Vulnerabilities
Page 3 of 10
CVE-2021-38924P3HIGHCVSS 7.5v7.6.1.1v7.6.1.22022-09-14
CVE-2021-38924 [HIGH] CWE-209 CVE-2021-38924: IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive in
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
nvd
CVE-2022-41734P3HIGHCVSS 7.5v7.6.1.2v7.6.1.3+1 more2023-02-17
CVE-2022-41734 [HIGH] CWE-200 CVE-2022-41734: IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive in
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.
nvd
CVE-2019-4591P3HIGHCVSS 7.8≥ 7.6.0.0, < 7.6.0.10≥ 7.6.1.0, < 7.6.1.1+2 more2020-07-13
CVE-2019-4591 [HIGH] CWE-384 CVE-2019-4591: IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could all
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
nvd
CVE-2013-3973P3MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+14 more2013-10-01
CVE-2013-3973 [MEDIUM] CWE-89 CVE-2013-3973: SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-0451P3MEDIUMCVSS 6.5v6.2v6.2.1+20 more2013-10-01
CVE-2013-0451 [MEDIUM] CWE-89 CVE-2013-0451: SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.1
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-2183P4MEDIUMCVSS 6.8v6.2.0.0v7.1.0.0+1 more2012-09-10
CVE-2012-2183 [MEDIUM] CVE-2012-2183: Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-3323P4MEDIUMCVSS 6.8v6.2v6.2.1+21 more2013-10-01
CVE-2012-3323 [MEDIUM] CWE-264 CVE-2012-3323: IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows rem
IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2015-4966P4MEDIUMCVSS 6.5v7.1v7.1.1+33 more2015-11-08
CVE-2015-4966 [MEDIUM] CWE-255 CVE-2015-4966: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other product
nvd
CVE-2012-2184P4MEDIUMCVSS 6.8v7.1.0.0v7.5.0.02012-09-10
CVE-2012-2184 [MEDIUM] CVE-2012-2184: Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-6355P4MEDIUMCVSS 6.5v6.2v6.2.1+19 more2013-02-20
CVE-2012-6355 [MEDIUM] CWE-264 CVE-2012-6355: IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tiv
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain
nvd
CVE-2019-4478P4MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2020-05-12
CVE-2019-4478 [MEDIUM] CVE-2019-4478: IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sens
IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
nvd
CVE-2018-2028P4MEDIUMCVSS 6.5v7.62019-06-06
CVE-2018-2028 [MEDIUM] CWE-312 CVE-2018-2028: IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
nvd
CVE-2019-4530P4MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2019-11-20
CVE-2019-4530 [MEDIUM] CVE-2019-4530: IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a re
IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.
nvd
CVE-2023-38723P4MEDIUMCVSS 6.4v7.6.1.32024-03-13
CVE-2023-38723 [MEDIUM] CWE-79 CVE-2023-38723: IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerabilit
IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262192.
nvd
CVE-2013-3047P4MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+13 more2013-10-01
CVE-2013-3047 [MEDIUM] CVE-2013-3047: IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated u
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2013-5381P4MEDIUMCVSS 6.5v6.2v6.2.1+23 more2013-10-01
CVE-2013-5381 [MEDIUM] CVE-2013-5381: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2013-4027P4MEDIUMCVSS 6.5v7.1v7.1.1+25 more2013-10-01
CVE-2013-4027 [MEDIUM] CWE-264 CVE-2013-4027: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-5465P4MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+12 more2014-05-26
CVE-2013-5465 [MEDIUM] CWE-264 CVE-2013-5465: IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-07
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Servic
nvd
CVE-2023-32337P4MEDIUMCVSS 5.4v7.6.1.32024-01-19
CVE-2023-32337 [MEDIUM] CWE-918 CVE-2023-32337: IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This m
IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 255288.
nvd
CVE-2025-2987P4MEDIUMCVSS 5.4v7.6.1.32025-04-22
CVE-2025-2987 [MEDIUM] CWE-918 CVE-2025-2987: IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may al
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd