Ibm Maximo Asset Management vulnerabilities
185 known vulnerabilities affecting ibm/maximo_asset_management.
Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26
Vulnerabilities
Page 8 of 10
CVE-2012-3323MEDIUMCVSS 6.8v6.2v6.2.1+21 more2013-10-01
CVE-2012-3323 [MEDIUM] CWE-264 CVE-2012-3323: IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows rem
IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2013-3973MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+14 more2013-10-01
CVE-2013-3973 [MEDIUM] CWE-89 CVE-2013-3973: SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-3972MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+14 more2013-10-01
CVE-2013-3972 [MEDIUM] CWE-200 CVE-2013-3972: IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated u
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-5382MEDIUMCVSS 4.0v6.2v6.2.1+24 more2013-10-01
CVE-2013-5382 [MEDIUM] CVE-2013-5382: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.
nvd
CVE-2013-3971MEDIUMCVSS 4.0v7.1v7.1.1+15 more2013-10-01
CVE-2013-3971 [MEDIUM] CVE-2013-3971: IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated
IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049.
nvd
CVE-2013-4018MEDIUMCVSS 6.0v7.1v7.1.1+23 more2013-10-01
CVE-2013-4018 [MEDIUM] CVE-2013-4018: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-3047MEDIUMCVSS 6.5v7.5.0.0v7.5.0.1+13 more2013-10-01
CVE-2013-3047 [MEDIUM] CVE-2013-3047: IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated u
IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2013-3049MEDIUMCVSS 4.0v7.1v7.1.1+15 more2013-10-01
CVE-2013-3049 [MEDIUM] CVE-2013-3049: IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated
IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971.
nvd
CVE-2013-0451MEDIUMCVSS 6.5v6.2v6.2.1+20 more2013-10-01
CVE-2013-0451 [MEDIUM] CWE-89 CVE-2013-0451: SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.1
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-4020MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+21 more2013-10-01
CVE-2013-4020 [MEDIUM] CVE-2013-4020: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-4027MEDIUMCVSS 6.5v7.1v7.1.1+25 more2013-10-01
CVE-2013-4027 [MEDIUM] CWE-264 CVE-2013-4027: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-5383MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+24 more2013-10-01
CVE-2013-5383 [MEDIUM] CVE-2013-5383: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382.
nvd
CVE-2013-4013MEDIUMCVSS 5.0v7.1v7.1.1+21 more2013-10-01
CVE-2013-4013 [MEDIUM] CVE-2013-4013: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-4017MEDIUMCVSS 6.5v7.1v7.1.1+9 more2013-10-01
CVE-2013-4017 [MEDIUM] CWE-89 CVE-2013-4017: SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attacke
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-5381MEDIUMCVSS 6.5v6.2v6.2.1+23 more2013-10-01
CVE-2013-5381 [MEDIUM] CVE-2013-5381: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows r
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2013-3048LOWCVSS 3.5v7.5.0.0v7.5.0.1+21 more2013-10-01
CVE-2013-3048 [LOW] CWE-79 CVE-2013-3048: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 throu
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-4019LOWCVSS 3.5v6.2v6.2.1+19 more2013-10-01
CVE-2013-4019 [LOW] CWE-79 CVE-2013-4019: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 be
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-5380LOWCVSS 2.1v7.1v7.1.1+24 more2013-10-01
CVE-2013-5380 [LOW] CWE-200 CVE-2013-5380: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows lo
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2012-3328MEDIUMCVSS 4.3v7.12013-02-20
CVE-2012-3328 [MEDIUM] CWE-79 CVE-2012-3328: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors relat
nvd
CVE-2012-6357MEDIUMCVSS 6.5v7.5.0.02013-02-20
CVE-2012-6357 [MEDIUM] CWE-264 CVE-2012-6357: IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk
IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.
nvd