Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown
CVE-2019-4048
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
0
Attacker Value
Unknown
CVE-2018-2028
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
0
Attacker Value
Unknown
CVE-2019-4056
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
0
Attacker Value
Unknown
CVE-2018-1528
Disclosure Date: August 06, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
0
Attacker Value
Unknown
CVE-2018-1524
Disclosure Date: August 03, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
0
Attacker Value
Unknown
CVE-2018-1415
Disclosure Date: February 22, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821.
0
Attacker Value
Unknown
CVE-2018-1414
Disclosure Date: February 22, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
0
Attacker Value
Unknown
CVE-2017-1499
Disclosure Date: February 14, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.
0
Attacker Value
Unknown
CVE-2017-1357
Disclosure Date: August 09, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
0
Attacker Value
Unknown
CVE-2017-1124
Disclosure Date: March 07, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.
0