cbcvebase.

Ibm Maximo For Nuclear Power vulnerabilities

44 known vulnerabilities affecting ibm/maximo_for_nuclear_power.

Total CVEs
44
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM30LOW9

Vulnerabilities

Page 1 of 3
CVE-2015-0104P2HIGHCVSS 8.8PoCv7.12017-04-24
CVE-2015-0104 [HIGH] CWE-284 CVE-2015-0104: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspeci
nvd
CVE-2015-0107P3MEDIUMCVSS 6.5PoCv7.12017-04-24
CVE-2015-0107 [MEDIUM] CWE-22 CVE-2015-0107: IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attac
nvd
CVE-2013-3323P3CRITICALCVSS 9.8v6.2v6.3+2 more2020-02-18
CVE-2013-3323 [CRITICAL] CWE-269 CVE-2013-3323: A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when W A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
nvd
CVE-2018-1524P3HIGHCVSS 8.8v7.6.0.02018-08-03
CVE-2018-1524 [HIGH] CVE-2018-1524: IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a r IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
nvd
CVE-2019-4364P3HIGHCVSS 8.0v7.6.02019-06-19
CVE-2019-4364 [HIGH] CWE-1236 CVE-2019-4364: IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authentic IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
nvd
CVE-2015-4967P3MEDIUMCVSS 6.5v7.1v7.5.0.0+6 more2015-10-06
CVE-2015-4967 [MEDIUM] CWE-89 CVE-2015-4967: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0. SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT
nvd
CVE-2020-4409P3HIGHCVSS 8.2v7.6.12020-09-16
CVE-2020-4409 [HIGH] CWE-601 CVE-2020-4409: IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attack IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obt
nvd
CVE-2015-7448P3MEDIUMCVSS 5.4v7.1v7.1.1+3 more2016-03-12
CVE-2015-7448 [MEDIUM] CWE-89 CVE-2015-7448: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0. SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Managemen
nvd
CVE-2015-4966P4MEDIUMCVSS 6.5v7.1v7.5.0.0+6 more2015-11-08
CVE-2015-4966 [MEDIUM] CWE-255 CVE-2015-4966: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other product
nvd
CVE-2018-2028P4MEDIUMCVSS 6.5v7.6.02019-06-06
CVE-2018-2028 [MEDIUM] CWE-312 CVE-2018-2028: IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
nvd
CVE-2015-5017P4MEDIUMCVSS 5.4v7.1v7.52016-01-03
CVE-2015-5017 [MEDIUM] CWE-284 CVE-2015-5017: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other pro
nvd
CVE-2019-4446P4MEDIUMCVSS 5.4v7.6.12020-04-17
CVE-2019-4446 [MEDIUM] CVE-2019-4446: IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not autho IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
nvd
CVE-2015-7396P4MEDIUMCVSS 5.4v7.52016-01-02
CVE-2015-7396 [MEDIUM] CWE-264 CVE-2015-7396: The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and M The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or modify data, via unspecified vecto
nvd
CVE-2019-4644P4MEDIUMCVSS 6.1v7.6.12020-04-17
CVE-2019-4644 [MEDIUM] CWE-79 CVE-2019-4644: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
nvd
CVE-2016-5896P4MEDIUMCVSS 5.3v7.62017-02-01
CVE-2016-5896 [MEDIUM] CWE-200 CVE-2016-5896: IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.
nvd
CVE-2015-1934P4MEDIUMCVSS 5.0v7.1v7.5.0.0+6 more2015-10-04
CVE-2015-1934 [MEDIUM] CWE-310 CVE-2015-1934: IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do
nvd
CVE-2016-5902P4MEDIUMCVSS 6.1v7.1v7.5+1 more2017-02-08
CVE-2016-5902 [MEDIUM] CWE-79 CVE-2016-5902: IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users t IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2019-4303P4MEDIUMCVSS 5.4v7.6.02019-06-19
CVE-2019-4303 [MEDIUM] CWE-79 CVE-2019-4303: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
nvd
CVE-2019-4749P4MEDIUMCVSS 5.4v7.6.12020-04-17
CVE-2019-4749 [MEDIUM] CWE-79 CVE-2019-4749: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
nvd
CVE-2019-4486P4MEDIUMCVSS 5.4v7.6.02019-10-24
CVE-2019-4486 [MEDIUM] CWE-79 CVE-2019-4486: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows use IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
nvd
Ibm Maximo For Nuclear Power vulnerabilities | cvebase