cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 7 of 10
CVE-2016-0222P4MEDIUMCVSS 4.3v7.6.0.0v7.6.0.1+2 more2016-03-14
CVE-2016-0222 [MEDIUM] CWE-284 CVE-2016-0222: IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass i IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.
nvd
CVE-2014-6194P4MEDIUMCVSS 4.0v7.1v7.1.1+20 more2015-02-17
CVE-2014-6194 [MEDIUM] CWE-22 CVE-2014-6194: Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 thro Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain
nvd
CVE-2016-5905P4MEDIUMCVSS 5.4v7.5.0.0v7.5.0.1+13 more2016-11-30
CVE-2016-5905 [MEDIUM] CWE-79 CVE-2016-5905: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.10 IF3 and 7.6 before 7.6.0.5 IF2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2018-1697P4MEDIUMCVSS 4.3v7.62018-12-05
CVE-2018-1697 [MEDIUM] CWE-200 CVE-2018-1697: IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a spe IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
nvd
CVE-2015-5051P4MEDIUMCVSS 4.3v7.5v7.62016-01-03
CVE-2015-5051 [MEDIUM] CWE-264 CVE-2015-5051: IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Manag IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow remote authenticated users to bypass intended access restrictions on query results via unspecified vectors.
nvd
CVE-2019-4056P4MEDIUMCVSS 4.3v7.62019-06-06
CVE-2019-4056 [MEDIUM] CWE-434 CVE-2019-4056: IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, a IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
nvd
CVE-2014-4765P4MEDIUMCVSS 5.0v7.1v7.1.1+20 more2014-10-02
CVE-2014-4765 [MEDIUM] CWE-200 CVE-2014-4765: IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7. IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by readi
nvd
CVE-2012-0195P4MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2012-0195 [MEDIUM] CWE-79 CVE-2012-0195: Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in I Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Manag
nvd
CVE-2018-1528P4MEDIUMCVSS 4.3≥ 7.6.0.0, ≤ 7.6.3.0v7.6+9 more2018-08-06
CVE-2018-1528 [MEDIUM] CWE-200 CVE-2018-1528: IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
nvd
CVE-2016-8987P4MEDIUMCVSS 4.3v7.1v7.5+2 more2017-06-08
CVE-2016-8987 [MEDIUM] CWE-200 CVE-2016-8987: IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect it IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
nvd
CVE-2013-4014P4MEDIUMCVSS 4.3v7.1v7.1.1+24 more2013-10-01
CVE-2013-4014 [MEDIUM] CWE-79 CVE-2013-4014: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 befor Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-3328P4MEDIUMCVSS 4.3v7.12013-02-20
CVE-2012-3328 [MEDIUM] CWE-79 CVE-2012-3328: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors relat
nvd
CVE-2012-3327P4MEDIUMCVSS 4.3v6.2v6.2.1+19 more2013-02-20
CVE-2012-3327 [MEDIUM] CWE-79 CVE-2012-3327: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asse Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.
nvd
CVE-2017-1357P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+19 more2017-08-09
CVE-2017-1357 [MEDIUM] CWE-20 CVE-2017-1357: IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
nvd
CVE-2015-7452P4MEDIUMCVSS 4.3v7.5v7.62016-01-02
CVE-2015-7452 [MEDIUM] CWE-200 CVE-2015-7452: IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Manag IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive information via the REST API.
nvd
CVE-2015-7395P4MEDIUMCVSS 4.0v7.1v7.1.1+24 more2015-11-08
CVE-2015-7395 [MEDIUM] CWE-284 CVE-2015-7395: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other product
nvd
CVE-2012-3326P4MEDIUMCVSS 4.3v7.5.0.02012-09-10
CVE-2012-3326 [MEDIUM] CWE-79 CVE-2012-3326: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud C Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-3313P4MEDIUMCVSS 4.3v6.2.0.0v7.1.0.0+1 more2012-09-10
CVE-2012-3313 [MEDIUM] CWE-79 CVE-2012-3313: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2019-4583P4MEDIUMCVSS 4.3v7.6.0.10v7.6.1.12020-02-20
CVE-2019-4583 [MEDIUM] CWE-209 CVE-2019-4583: IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensiti IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289.
nvd
CVE-2015-0108P4MEDIUMCVSS 4.3v7.1v7.1.1+6 more2015-02-18
CVE-2015-0108 [MEDIUM] CVE-2015-0108: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Max Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CV
nvd
Ibm Maximo Asset Management vulnerabilities | cvebase