cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 4 of 10
CVE-2012-0714P4MEDIUMCVSS 6.8v6.2.0.0v7.1.0.0+1 more2012-09-10
CVE-2012-0714 [MEDIUM] CWE-352 CVE-2012-0714: Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as u Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims vi
nvd
CVE-2016-8924P4MEDIUMCVSS 5.6v7.1v7.5+1 more2017-04-26
CVE-2016-8924 [MEDIUM] CWE-79 CVE-2016-8924: IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's sessio IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
nvd
CVE-2011-1397P4MEDIUMCVSS 6.8v6.2v7.1+1 more2012-03-13
CVE-2011-1397 [MEDIUM] CWE-352 CVE-2011-1397: Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Mana Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCM
nvd
CVE-2013-4021P4MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+24 more2013-10-01
CVE-2013-4021 [MEDIUM] CVE-2013-4021: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified file-inclusion attacks via unknown vectors.
nvd
CVE-2012-6357P4MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6357 [MEDIUM] CWE-264 CVE-2012-6357: IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.
nvd
CVE-2012-6356P4MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6356 [MEDIUM] CWE-264 CVE-2012-6356: IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges via vectors related to an import operation.
nvd
CVE-2015-5017P4MEDIUMCVSS 5.4v7.1v7.5+1 more2016-01-03
CVE-2015-5017 [MEDIUM] CWE-284 CVE-2015-5017: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other pro
nvd
CVE-2018-1698P4MEDIUMCVSS 5.3≥ 7.6, ≤ 7.6.3v7.6+9 more2018-09-13
CVE-2018-1698 [MEDIUM] CWE-200 CVE-2018-1698: IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sens IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.
nvd
CVE-2019-4446P4MEDIUMCVSS 5.4v7.6.0v7.6.1+2 more2020-04-17
CVE-2019-4446 [MEDIUM] CVE-2019-4446: IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not autho IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
nvd
CVE-2014-3084P4MEDIUMCVSS 4.9v6.1v6.2+31 more2014-08-29
CVE-2014-3084 [MEDIUM] CWE-264 CVE-2014-3084: IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo A IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass inte
nvd
CVE-2019-4582P4MEDIUMCVSS 4.3v7.6.0.0v7.6.0.1+2 more2020-08-13
CVE-2019-4582 [MEDIUM] CWE-22 CVE-2019-4582: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 167288.
nvd
CVE-2013-5464P4MEDIUMCVSS 6.0v7.5.0.0v7.5.0.1+4 more2014-05-26
CVE-2013-5464 [MEDIUM] CWE-264 CVE-2013-5464: IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to bypass intended access restrictions, and modify physical counts associated with restricted storerooms, via unspecified vectors.
nvd
CVE-2017-1352P4MEDIUMCVSS 5.5v7.5v7.62017-09-12
CVE-2017-1352 [MEDIUM] CWE-77 CVE-2017-1352: IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into wo IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
nvd
CVE-2015-7396P4MEDIUMCVSS 5.4v7.5v7.62016-01-02
CVE-2015-7396 [MEDIUM] CWE-264 CVE-2015-7396: The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and M The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vecto
nvd
CVE-2014-0849P4MEDIUMCVSS 6.0v7.1v7.1.1+15 more2014-05-26
CVE-2014-0849 [MEDIUM] CWE-264 CVE-2014-0849: IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0. IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authenticated users to gain privileges by leveraging membership in two security groups.
nvd
CVE-2023-32332P4MEDIUMCVSS 5.4v7.6.1.2v7.6.1.3+1 more2023-09-08
CVE-2023-32332 [MEDIUM] CWE-79 CVE-2023-32332: IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerab IBM Maximo Application Suite 8.9, 8.10 and IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 255072.
nvd
CVE-2023-32334P4MEDIUMCVSS 5.3v7.6.1.2v7.6.1.3+1 more2023-06-05
CVE-2023-32334 [MEDIUM] CVE-2023-32334: IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.
nvd
CVE-2025-2986P4MEDIUMCVSS 5.4v7.6.1.32025-04-25
CVE-2025-2986 [MEDIUM] CWE-79 CVE-2025-2986: IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2017-1558P4MEDIUMCVSS 6.1v7.5v7.62017-12-13
CVE-2017-1558 [MEDIUM] CWE-601 CVE-2017-1558: IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, u IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This co
nvd
CVE-2019-4644P4MEDIUMCVSS 6.1v7.6.1.1v7.62020-04-17
CVE-2019-4644 [MEDIUM] CWE-79 CVE-2019-4644: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
nvd
Ibm Maximo Asset Management vulnerabilities | cvebase