Ibm Maximo For Life Sciences vulnerabilities

44 known vulnerabilities affecting ibm/maximo_for_life_sciences.

Total CVEs
44
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM30LOW9

Vulnerabilities

Page 1 of 3
CVE-2020-4409HIGHCVSS 8.2v7.62020-09-16
CVE-2020-4409 [HIGH] CWE-601 CVE-2020-4409: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attack IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obt
nvd
CVE-2019-4749MEDIUMCVSS 5.4v7.62020-04-17
CVE-2019-4749 [MEDIUM] CWE-79 CVE-2019-4749: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
nvd
CVE-2019-4446MEDIUMCVSS 5.4v7.62020-04-17
CVE-2019-4446 [MEDIUM] CVE-2019-4446: IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not autho IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
nvd
CVE-2019-4644MEDIUMCVSS 6.1v7.62020-04-17
CVE-2019-4644 [MEDIUM] CWE-79 CVE-2019-4644: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
nvd
CVE-2019-4745MEDIUMCVSS 4.3v7.62020-02-24
CVE-2019-4745 [MEDIUM] CWE-863 CVE-2019-4745: IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
nvd
CVE-2019-4429MEDIUMCVSS 5.4v7.62020-02-19
CVE-2019-4429 [MEDIUM] CWE-79 CVE-2019-4429: IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerabilit IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
nvd
CVE-2013-3323CRITICALCVSS 9.8v6.2v6.4+3 more2020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2019-4486MEDIUMCVSS 5.4v7.62019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
nvd
CVE-2019-4512MEDIUMCVSS 4.3v7.62019-10-09
CVE-2019-4512 [MEDIUM] CWE-209 CVE-2019-4512: IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information t IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
nvd
CVE-2019-4364HIGHCVSS 8.0v7.62019-06-19
CVE-2019-4364 [HIGH] CWE-1236 CVE-2019-4364: IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authentic IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
nvd
CVE-2019-4303MEDIUMCVSS 5.4v7.62019-06-19
CVE-2019-4303 [MEDIUM] CWE-79 CVE-2019-4303: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
nvd
CVE-2019-4056MEDIUMCVSS 4.3v7.62019-06-06
CVE-2019-4056 [MEDIUM] CWE-434 CVE-2019-4056: IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, a IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
nvd
CVE-2018-2028MEDIUMCVSS 6.5v7.62019-06-06
CVE-2018-2028 [MEDIUM] CWE-312 CVE-2018-2028: IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
nvd
CVE-2019-4048LOWCVSS 2.1v7.62019-06-06
CVE-2019-4048 [LOW] CWE-269 CVE-2019-4048: IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive inform IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
nvd
CVE-2018-1528MEDIUMCVSS 4.3v7.6.0.02018-08-06
CVE-2018-1528 [MEDIUM] CWE-200 CVE-2018-1528: IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
nvd
CVE-2018-1524HIGHCVSS 8.8v7.6.0.02018-08-03
CVE-2018-1524 [HIGH] CVE-2018-1524: IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a r IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
nvd
CVE-2015-5016MEDIUMCVSS 4.3v7.1v7.5+1 more2018-03-27
CVE-2015-5016 [MEDIUM] CWE-200 CVE-2015-5016: IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Contr IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 10
nvd
CVE-2015-0104HIGHCVSS 8.8PoCv7.12017-04-24
CVE-2015-0104 [HIGH] CWE-284 CVE-2015-0104: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspeci
nvd
CVE-2015-0107MEDIUMCVSS 6.5PoCv7.12017-04-24
CVE-2015-0107 [MEDIUM] CWE-22 CVE-2015-0107: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attac
nvd
CVE-2016-5902MEDIUMCVSS 6.1v7.1v7.5+1 more2017-02-08
CVE-2016-5902 [MEDIUM] CWE-79 CVE-2016-5902: IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users t IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd