cbcvebase.

Ibm Maximo Asset Management vulnerabilities

185 known vulnerabilities affecting ibm/maximo_asset_management.

Total CVEs
185
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH26MEDIUM128LOW26

Vulnerabilities

Page 8 of 10
CVE-2019-4745P4MEDIUMCVSS 4.3v7.6.1.02020-02-24
CVE-2019-4745 [MEDIUM] CWE-863 CVE-2019-4745: IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
nvd
CVE-2016-0289P4MEDIUMCVSS 4.3v7.1v7.5+15 more2016-04-05
CVE-2016-0289 [MEDIUM] CWE-284 CVE-2016-0289: shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 an shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified vectors.
nvd
CVE-2020-4526P4MEDIUMCVSS 4.3≥ 7.6.0, < 7.6.0.10≥ 7.6.1, < 7.6.1.2+2 more2020-09-15
CVE-2020-4526 [MEDIUM] CWE-352 CVE-2020-4526: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 182436.
nvd
CVE-2013-4020P4MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+21 more2013-10-01
CVE-2013-4020 [MEDIUM] CVE-2013-4020: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows r IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-5382P4MEDIUMCVSS 4.0v6.2v6.2.1+24 more2013-10-01
CVE-2013-5382 [MEDIUM] CVE-2013-5382: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.
nvd
CVE-2013-5383P4MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+24 more2013-10-01
CVE-2013-5383 [MEDIUM] CVE-2013-5383: IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows re IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382.
nvd
CVE-2014-0893P4MEDIUMCVSS 4.3v7.5.0.0v7.5.0.1+4 more2014-05-26
CVE-2014-0893 [MEDIUM] CWE-79 CVE-2014-0893: Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x be Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.
nvd
CVE-2011-4819P4MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2011-4819 [MEDIUM] CWE-79 CVE-2011-4819: Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Managem Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.
nvd
CVE-2011-1395P4MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2011-1395 [MEDIUM] CWE-79 CVE-2011-1395: Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Mana Cross-site scripting (XSS) vulnerability in imicon.jsp in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the controlid parameter.
nvd
CVE-2011-1396P4MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2011-1396 [MEDIUM] CWE-79 CVE-2011-1396: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essenti Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote attackers to inject arbitrary web script or HTML via the reportType parameter to an unspecified component.
nvd
CVE-2014-3026P4LOWCVSS 3.5v7.5.0.0v7.5.0.1+5 more2014-07-29
CVE-2014-3026 [LOW] CVE-2014-3026: CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5 CRLF injection vulnerability in IBM Maximo Asset Management 7.5 through 7.5.0.6, and 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2011-4818P4MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2011-4818 [MEDIUM] CWE-20 CVE-2011-4818: Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the uisessionid parameter to an unspecified component.
nvd
CVE-2019-4512P4MEDIUMCVSS 4.3v7.6.1.12019-10-09
CVE-2019-4512 [MEDIUM] CWE-209 CVE-2019-4512: IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information t IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
nvd
CVE-2011-4817P4MEDIUMCVSS 4.0v6.2v7.1+1 more2012-03-13
CVE-2011-4817 [MEDIUM] CWE-200 CVE-2011-4817: The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2 The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username,
nvd
CVE-2013-3971P4MEDIUMCVSS 4.0v7.1v7.1.1+15 more2013-10-01
CVE-2013-3971 [MEDIUM] CVE-2013-3971: IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049.
nvd
CVE-2013-3049P4MEDIUMCVSS 4.0v7.1v7.1.1+15 more2013-10-01
CVE-2013-3049 [MEDIUM] CVE-2013-3049: IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971.
nvd
CVE-2015-4965P4MEDIUMCVSS 4.0v7.1v7.1.1+21 more2015-10-06
CVE-2015-4965 [MEDIUM] CWE-200 CVE-2015-4965: maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1. maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT
nvd
CVE-2013-3972P4MEDIUMCVSS 4.0v7.5.0.0v7.5.0.1+14 more2013-10-01
CVE-2013-3972 [MEDIUM] CWE-200 CVE-2013-3972: IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated u IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2012-2185P4MEDIUMCVSS 4.0v6.2.0.0v7.1.0.0+1 more2012-09-10
CVE-2012-2185 [MEDIUM] CWE-200 CVE-2012-2185: IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Manage IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2015-7487P4MEDIUMCVSS 4.1v7.1v7.1.1+27 more2016-01-27
CVE-2015-7487 [MEDIUM] CWE-200 CVE-2015-7487: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other pro
nvd
Ibm Maximo Asset Management vulnerabilities | cvebase