cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 6 of 10
CVE-2018-1415P4MEDIUMCVSS 5.4v7.6.0.5v7.6.0.6+3 more2018-02-22
CVE-2018-1415 [MEDIUM] CWE-79 CVE-2018-1415: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821.
nvd
CVE-2017-1208P4MEDIUMCVSS 5.4v7.1v7.1.1+2 more2017-07-05
CVE-2017-1208 [MEDIUM] CWE-79 CVE-2017-1208: IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerabil IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
nvd
CVE-2018-1715P4MEDIUMCVSS 5.4≤ 7.6.3.0v7.6+9 more2018-08-16
CVE-2018-1715 [MEDIUM] CWE-79 CVE-2018-1715: IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerabil IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.
nvd
CVE-2019-4749P4MEDIUMCVSS 5.4v7.6.1.1v7.62020-04-17
CVE-2019-4749 [MEDIUM] CWE-79 CVE-2019-4749: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
nvd
CVE-2019-4486P4MEDIUMCVSS 5.4≥ 7.6.0.0, < 7.6.0.10≥ 7.6.1.0, < 7.6.1.1+1 more2019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
nvd
CVE-2018-1686P4MEDIUMCVSS 5.4≥ 7.6, ≤ 7.6.3v7.6+9 more2018-10-05
CVE-2018-1686 [MEDIUM] CWE-79 CVE-2018-1686: IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerabil IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145505.
nvd
CVE-2015-7451P4MEDIUMCVSS 5.4v7.5v7.62016-01-02
CVE-2015-7451 [MEDIUM] CWE-79 CVE-2015-7451: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2020-4223P4MEDIUMCVSS 5.4v7.6.0.10v7.6.1.12020-06-26
CVE-2020-4223 [MEDIUM] CWE-79 CVE-2020-4223: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnera IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175121.
nvd
CVE-2019-4429P4MEDIUMCVSS 5.4v7.6.0v7.6.12020-02-19
CVE-2019-4429 [MEDIUM] CWE-79 CVE-2019-4429: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
nvd
CVE-2016-6072P4MEDIUMCVSS 5.4v7.6.0.02017-02-01
CVE-2016-6072 [MEDIUM] CWE-79 CVE-2016-6072: IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users t IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2022-35714P4MEDIUMCVSS 5.4v7.6.1.1v7.6.1.22022-08-26
CVE-2022-35714 [MEDIUM] CWE-79 CVE-2022-35714: IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows u IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116.
nvd
CVE-2022-43866P4MEDIUMCVSS 5.4v7.6.1.2v7.6.1.3+1 more2023-05-05
CVE-2022-43866 [MEDIUM] CWE-79 CVE-2022-43866: IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerab IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239436.
nvd
CVE-2013-4013P4MEDIUMCVSS 5.0v7.1v7.1.1+21 more2013-10-01
CVE-2013-4013 [MEDIUM] CVE-2013-4013: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows r IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2011-1394P4MEDIUMCVSS 5.0v6.2v7.1+1 more2012-03-13
CVE-2011-1394 [MEDIUM] CWE-399 CVE-2011-1394: IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Mana IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allow remote attackers to cause a denial of service (memo
nvd
CVE-2016-0393P4MEDIUMCVSS 5.3v7.5.0.0v7.5.0.1+15 more2016-07-17
CVE-2016-0393 [MEDIUM] CWE-200 CVE-2016-0393: IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP0 IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
nvd
CVE-2016-0399P4MEDIUMCVSS 5.4v7.1v7.1.1+26 more2016-07-02
CVE-2016-0399 [MEDIUM] CWE-79 CVE-2016-0399: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 be Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-0262P4MEDIUMCVSS 5.4v7.1.1v7.1.1.1+16 more2016-03-14
CVE-2016-0262 [MEDIUM] CWE-79 CVE-2016-0262: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2017-1292P4MEDIUMCVSS 5.3v7.5v7.62017-05-26
CVE-2017-1292 [MEDIUM] CWE-200 CVE-2017-1292: IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive informa IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.
nvd
CVE-2023-27860P4MEDIUMCVSS 5.3v7.6.1.2v7.6.1.3+1 more2023-04-27
CVE-2023-27860 [MEDIUM] CWE-209 CVE-2023-27860: IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error mes IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. IBM X-Force ID: 249207.
nvd
CVE-2015-5016P4MEDIUMCVSS 4.3v7.1v7.5+1 more2018-03-27
CVE-2015-5016 [MEDIUM] CWE-200 CVE-2015-5016: IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Contr IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 10
nvd
Ibm Maximo Asset Management vulnerabilities | cvebase