cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 5 of 10
CVE-2014-3024P4MEDIUMCVSS 6.0v7.1v7.1.1+18 more2014-08-29
CVE-2014-3024 [MEDIUM] CWE-352 CVE-2014-3024: Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.
nvd
CVE-2016-5987P4MEDIUMCVSS 5.3v7.1.0.0v7.1.1+29 more2016-11-30
CVE-2016-5987 [MEDIUM] CWE-20 CVE-2016-5987: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive information via a crafted HTTP request that triggers construction of a runtime error message.
nvd
CVE-2016-5896P4MEDIUMCVSS 5.3v7.62017-02-01
CVE-2016-5896 [MEDIUM] CWE-200 CVE-2016-5896: IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
nvd
CVE-2017-1291P4MEDIUMCVSS 5.4v7.5v7.62017-05-26
CVE-2017-1291 [MEDIUM] CWE-79 CVE-2017-1291: IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote a IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and
nvd
CVE-2021-20374P4MEDIUMCVSS 5.4v7.6.0v7.6.12021-05-19
CVE-2021-20374 [MEDIUM] CWE-79 CVE-2021-20374: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulne IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522.
nvd
CVE-2021-29743P4MEDIUMCVSS 5.4≥ 7.6.0.0, ≤ 7.6.0.10≥ 7.6.1.0, ≤ 7.6.1.2+2 more2021-08-30
CVE-2021-29743 [MEDIUM] CWE-79 CVE-2021-29743: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulne IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693.
nvd
CVE-2021-29744P4MEDIUMCVSS 5.4v7.6.0.0v7.6.0.1+2 more2021-08-27
CVE-2021-29744 [MEDIUM] CWE-79 CVE-2021-29744: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694.
nvd
CVE-2022-35645P4MEDIUMCVSS 5.4v7.6.1.1v7.6.1.2+2 more2023-03-02
CVE-2022-35645 [MEDIUM] CWE-79 CVE-2022-35645: IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 i IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force I
nvd
CVE-2023-27864P4MEDIUMCVSS 5.4v7.6.1.2v7.6.1.3+1 more2023-04-28
CVE-2023-27864 [MEDIUM] CWE-79 CVE-2023-27864: IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker c IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 249327.
nvd
CVE-2022-22435P4MEDIUMCVSS 5.4v7.6.1.22022-04-21
CVE-2022-22435 [MEDIUM] CWE-79 CVE-2022-22435: IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2022-22436P4MEDIUMCVSS 5.4v7.6.1.22022-04-21
CVE-2022-22436 [MEDIUM] CWE-79 CVE-2022-22436: IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224164.
nvd
CVE-2024-45088P4MEDIUMCVSS 5.4v7.6.1.32024-11-11
CVE-2024-45088 [MEDIUM] CWE-79 CVE-2024-45088: IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2015-1934P4MEDIUMCVSS 5.0v7.1v7.1.1+21 more2015-10-04
CVE-2015-1934 [MEDIUM] CWE-310 CVE-2015-1934: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do
nvd
CVE-2012-3333P4MEDIUMCVSS 4.3v7.1v7.1.1+17 more2014-05-26
CVE-2012-3333 [MEDIUM] CVE-2012-3333: CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Contro CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.
nvd
CVE-2016-5902P4MEDIUMCVSS 6.1v7.1v7.5+1 more2017-02-08
CVE-2016-5902 [MEDIUM] CWE-79 CVE-2016-5902: IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users t IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2013-4018P4MEDIUMCVSS 6.0v7.1v7.1.1+23 more2013-10-01
CVE-2013-4018 [MEDIUM] CVE-2013-4018: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-4303P4MEDIUMCVSS 5.4v7.62019-06-19
CVE-2019-4303 [MEDIUM] CWE-79 CVE-2019-4303: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
nvd
CVE-2018-1584P4MEDIUMCVSS 5.4v7.62018-11-28
CVE-2018-1584 [MEDIUM] CWE-79 CVE-2018-1584: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 143497.
nvd
CVE-2018-1872P4MEDIUMCVSS 5.4v7.62018-11-09
CVE-2018-1872 [MEDIUM] CWE-79 CVE-2018-1872: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151330.
nvd
CVE-2018-1554P4MEDIUMCVSS 5.4≥ 7.6.0.0, < 7.6.1.0v7.62018-08-02
CVE-2018-1554 [MEDIUM] CWE-79 CVE-2018-1554: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142891.
nvd
Ibm Maximo Asset Management vulnerabilities | cvebase