Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 3 of 10
CVE-2020-4223MEDIUMCVSS 5.4v7.6.0.10v7.6.1.12020-06-26
CVE-2020-4223 [MEDIUM] CWE-79 CVE-2020-4223: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnera IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175121.
cvelistv5nvd
CVE-2020-4529HIGHCVSS 7.4v7.6.0.0v7.6.1.0+2 more2020-06-08
CVE-2020-4529 [HIGH] CWE-918 CVE-2020-4529: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). Thi IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
cvelistv5nvd
CVE-2019-4478MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2020-05-12
CVE-2019-4478 [MEDIUM] CVE-2019-4478: IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sens IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
cvelistv5nvd
CVE-2019-4749MEDIUMCVSS 5.4v7.6.1.1v7.62020-04-17
CVE-2019-4749 [MEDIUM] CWE-79 CVE-2019-4749: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
cvelistv5nvd
CVE-2019-4446MEDIUMCVSS 5.4v7.6.0v7.6.1+2 more2020-04-17
CVE-2019-4446 [MEDIUM] CVE-2019-4446: IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not autho IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
cvelistv5nvd
CVE-2019-4644MEDIUMCVSS 6.1v7.6.1.1v7.62020-04-17
CVE-2019-4644 [MEDIUM] CWE-79 CVE-2019-4644: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
cvelistv5nvd
CVE-2019-4745MEDIUMCVSS 4.3v7.6.1.02020-02-24
CVE-2019-4745 [MEDIUM] CWE-863 CVE-2019-4745: IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
cvelistv5nvd
CVE-2019-4583MEDIUMCVSS 4.3v7.6.0.10v7.6.1.12020-02-20
CVE-2019-4583 [MEDIUM] CWE-209 CVE-2019-4583: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensiti IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289.
cvelistv5nvd
CVE-2019-4429MEDIUMCVSS 5.4v7.6.0v7.6.12020-02-19
CVE-2019-4429 [MEDIUM] CWE-79 CVE-2019-4429: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
cvelistv5nvd
CVE-2013-3323CRITICALCVSS 9.8v6.2v7.1+1 more2020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2019-4530MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2019-11-20
CVE-2019-4530 [MEDIUM] CVE-2019-4530: IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a re IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.
cvelistv5nvd
CVE-2019-4486MEDIUMCVSS 5.4≥ 7.6.0.0, < 7.6.0.10≥ 7.6.1.0, < 7.6.1.1+1 more2019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
cvelistv5nvd
CVE-2019-4512MEDIUMCVSS 4.3v7.6.1.12019-10-09
CVE-2019-4512 [MEDIUM] CWE-209 CVE-2019-4512: IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information t IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
cvelistv5nvd
CVE-2019-4430HIGHCVSS 7.5v7.62019-07-17
CVE-2019-4430 [HIGH] CWE-22 CVE-2019-4430: IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
cvelistv5nvd
CVE-2019-4364HIGHCVSS 8.0v7.62019-06-19
CVE-2019-4364 [HIGH] CWE-1236 CVE-2019-4364: IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authentic IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
cvelistv5nvd
CVE-2019-4303MEDIUMCVSS 5.4v7.62019-06-19
CVE-2019-4303 [MEDIUM] CWE-79 CVE-2019-4303: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
cvelistv5nvd
CVE-2019-4056MEDIUMCVSS 4.3v7.62019-06-06
CVE-2019-4056 [MEDIUM] CWE-434 CVE-2019-4056: IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, a IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
cvelistv5nvd
CVE-2018-2028MEDIUMCVSS 6.5v7.62019-06-06
CVE-2018-2028 [MEDIUM] CWE-312 CVE-2018-2028: IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
cvelistv5nvd
CVE-2019-4048LOWCVSS 2.1v7.62019-06-06
CVE-2019-4048 [LOW] CWE-269 CVE-2019-4048: IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive inform IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
cvelistv5nvd
CVE-2018-1697MEDIUMCVSS 4.3v7.62018-12-05
CVE-2018-1697 [MEDIUM] CWE-200 CVE-2018-1697: IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a spe IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
cvelistv5nvd