Ibm Maximo Asset Management vulnerabilities
185 known vulnerabilities affecting ibm/maximo_asset_management.
Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26
Vulnerabilities
Page 3 of 10
CVE-2020-4223MEDIUMCVSS 5.4v7.6.0.10v7.6.1.12020-06-26
CVE-2020-4223 [MEDIUM] CWE-79 CVE-2020-4223: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnera
IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175121.
cvelistv5nvd
CVE-2020-4529HIGHCVSS 7.4v7.6.0.0v7.6.1.0+2 more2020-06-08
CVE-2020-4529 [HIGH] CWE-918 CVE-2020-4529: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). Thi
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
cvelistv5nvd
CVE-2019-4478MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2020-05-12
CVE-2019-4478 [MEDIUM] CVE-2019-4478: IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sens
IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
cvelistv5nvd
CVE-2019-4749MEDIUMCVSS 5.4v7.6.1.1v7.62020-04-17
CVE-2019-4749 [MEDIUM] CWE-79 CVE-2019-4749: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
cvelistv5nvd
CVE-2019-4446MEDIUMCVSS 5.4v7.6.0v7.6.1+2 more2020-04-17
CVE-2019-4446 [MEDIUM] CVE-2019-4446: IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not autho
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
cvelistv5nvd
CVE-2019-4644MEDIUMCVSS 6.1v7.6.1.1v7.62020-04-17
CVE-2019-4644 [MEDIUM] CWE-79 CVE-2019-4644: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
cvelistv5nvd
CVE-2019-4745MEDIUMCVSS 4.3v7.6.1.02020-02-24
CVE-2019-4745 [MEDIUM] CWE-863 CVE-2019-4745: IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
cvelistv5nvd
CVE-2019-4583MEDIUMCVSS 4.3v7.6.0.10v7.6.1.12020-02-20
CVE-2019-4583 [MEDIUM] CWE-209 CVE-2019-4583: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensiti
IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289.
cvelistv5nvd
CVE-2019-4429MEDIUMCVSS 5.4v7.6.0v7.6.12020-02-19
CVE-2019-4429 [MEDIUM] CWE-79 CVE-2019-4429: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
cvelistv5nvd
CVE-2013-3323CRITICALCVSS 9.8v6.2v7.1+1 more2020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2019-4530MEDIUMCVSS 6.5v7.6.0.0v7.6.1+2 more2019-11-20
CVE-2019-4530 [MEDIUM] CVE-2019-4530: IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a re
IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.
cvelistv5nvd
CVE-2019-4486MEDIUMCVSS 5.4≥ 7.6.0.0, < 7.6.0.10≥ 7.6.1.0, < 7.6.1.1+1 more2019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
cvelistv5nvd
CVE-2019-4512MEDIUMCVSS 4.3v7.6.1.12019-10-09
CVE-2019-4512 [MEDIUM] CWE-209 CVE-2019-4512: IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information t
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
cvelistv5nvd
CVE-2019-4430HIGHCVSS 7.5v7.62019-07-17
CVE-2019-4430 [HIGH] CWE-22 CVE-2019-4430: IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system.
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.
cvelistv5nvd
CVE-2019-4364HIGHCVSS 8.0v7.62019-06-19
CVE-2019-4364 [HIGH] CWE-1236 CVE-2019-4364: IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authentic
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
cvelistv5nvd
CVE-2019-4303MEDIUMCVSS 5.4v7.62019-06-19
CVE-2019-4303 [MEDIUM] CWE-79 CVE-2019-4303: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
cvelistv5nvd
CVE-2019-4056MEDIUMCVSS 4.3v7.62019-06-06
CVE-2019-4056 [MEDIUM] CWE-434 CVE-2019-4056: IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, a
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
cvelistv5nvd
CVE-2018-2028MEDIUMCVSS 6.5v7.62019-06-06
CVE-2018-2028 [MEDIUM] CWE-312 CVE-2018-2028: IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
cvelistv5nvd
CVE-2019-4048LOWCVSS 2.1v7.62019-06-06
CVE-2019-4048 [LOW] CWE-269 CVE-2019-4048: IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive inform
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
cvelistv5nvd
CVE-2018-1697MEDIUMCVSS 4.3v7.62018-12-05
CVE-2018-1697 [MEDIUM] CWE-200 CVE-2018-1697: IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a spe
IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
cvelistv5nvd