Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown

CVE-2019-4303

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
Attacker Value
Unknown

CVE-2019-4048

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
Attacker Value
Unknown

CVE-2018-2028

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
Attacker Value
Unknown

CVE-2019-4056

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
Attacker Value
Unknown

CVE-2018-1528

Disclosure Date: August 06, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
0
Attacker Value
Unknown

CVE-2018-1524

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
0
Attacker Value
Unknown

CVE-2015-5016

Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown

CVE-2015-0107

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-0104

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-5902

Disclosure Date: February 08, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0