Ibm Tivoli Asset Management For It vulnerabilities
44 known vulnerabilities affecting ibm/tivoli_asset_management_for_it.
Total CVEs
44
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM33LOW9
Vulnerabilities
Page 2 of 3
CVE-2013-4016MEDIUMCVSS 6.5v7.0v7.12014-05-26
CVE-2013-4016 [MEDIUM] CWE-89 CVE-2013-4016: SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7
SQL injection vulnerability in IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management
nvd
CVE-2013-5465MEDIUMCVSS 6.5v7.0v7.12014-05-26
CVE-2013-5465 [MEDIUM] CWE-264 CVE-2013-5465: IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-07
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x before 7.5.0.3 IFIX027, and 7.5.0.4 before IFIX011; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Servic
nvd
CVE-2013-6741LOWCVSS 3.5v7.0v7.12014-05-26
CVE-2013-6741 [LOW] CWE-200 CVE-2013-6741: IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006;
IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.x before 7.1.1.7 LAFIX.20140319-0
nvd
CVE-2013-5402LOWCVSS 3.5v7.1.1.12v7.1.2+2 more2013-12-18
CVE-2013-5402 [LOW] CWE-79 CVE-2013-5402: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Ess
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud
nvd
CVE-2012-3328MEDIUMCVSS 4.3v7.1v7.22013-02-20
CVE-2012-3328 [MEDIUM] CWE-79 CVE-2012-3328: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors relat
nvd
CVE-2012-6355MEDIUMCVSS 6.5v6.0v6.2+3 more2013-02-20
CVE-2012-6355 [MEDIUM] CWE-264 CVE-2012-6355: IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tiv
IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain
nvd
CVE-2012-3327MEDIUMCVSS 4.3v6.0v6.2+3 more2013-02-20
CVE-2012-3327 [MEDIUM] CWE-79 CVE-2012-3327: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asse
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.
nvd
CVE-2012-3322LOWCVSS 3.5v6.0v6.2+3 more2013-02-20
CVE-2012-3322 [LOW] CWE-79 CVE-2012-3322: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asse
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 a
nvd
CVE-2012-3316LOWCVSS 3.5v6.0v6.2+3 more2013-02-20
CVE-2012-3316 [LOW] CWE-79 CVE-2012-3316: Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maxim
Cross-site scripting (XSS) vulnerability in the Tivoli Process Automation Engine (TPAE) in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB)
nvd
CVE-2012-0728MEDIUMCVSS 6.5v6.0v6.2+3 more2012-09-10
CVE-2012-0728 [MEDIUM] CWE-89 CVE-2012-0728: SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Co
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-0727MEDIUMCVSS 6.5v6.0v6.2+3 more2012-09-10
CVE-2012-0727 [MEDIUM] CWE-89 CVE-2012-0727: SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk,
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-2184MEDIUMCVSS 6.8v6.0v6.2+3 more2012-09-10
CVE-2012-2184 [MEDIUM] CVE-2012-2184: Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-0714MEDIUMCVSS 6.8v6.0v6.2+3 more2012-09-10
CVE-2012-0714 [MEDIUM] CWE-352 CVE-2012-0714: Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as u
Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims vi
nvd
CVE-2012-3326MEDIUMCVSS 4.3v6.0v6.2+3 more2012-09-10
CVE-2012-3326 [MEDIUM] CWE-79 CVE-2012-3326: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud C
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0747MEDIUMCVSS 6.5v6.0v6.2+3 more2012-09-10
CVE-2012-0747 [MEDIUM] CWE-89 CVE-2012-0747: SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Co
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2012-3313MEDIUMCVSS 4.3v6.0v6.2+3 more2012-09-10
CVE-2012-3313 [MEDIUM] CWE-79 CVE-2012-3313: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-2183MEDIUMCVSS 6.8v6.0v6.2+3 more2012-09-10
CVE-2012-2183 [MEDIUM] CVE-2012-2183: Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud
Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.
nvd
CVE-2012-2185MEDIUMCVSS 4.0v6.0v6.2+3 more2012-09-10
CVE-2012-2185 [MEDIUM] CWE-200 CVE-2012-2185: IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Manage
IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.
nvd
CVE-2012-0746LOWCVSS 3.5v6.0v6.2+3 more2012-09-10
CVE-2012-0746 [LOW] CWE-79 CVE-2012-0746: Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud C
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-0195MEDIUMCVSS 4.3v6.2v7.1+1 more2012-03-13
CVE-2012-0195 [MEDIUM] CWE-79 CVE-2012-0195: Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in I
Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Manag
nvd