Show filters
182 Total Results
Displaying 71-80 of 182
Sort by:
Attacker Value
Unknown

CVE-2017-1558

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548.
0
Attacker Value
Unknown

CVE-2017-1352

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
0
Attacker Value
Unknown

CVE-2017-1357

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.
0
Attacker Value
Unknown

CVE-2017-1208

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
0
Attacker Value
Unknown

CVE-2017-1176

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.
0
Attacker Value
Unknown

CVE-2017-1175

Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
0
Attacker Value
Unknown

CVE-2016-9984

Disclosure Date: June 13, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
0
Attacker Value
Unknown

CVE-2016-8987

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
0
Attacker Value
Unknown

CVE-2016-9977

Disclosure Date: June 07, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
0
Attacker Value
Unknown

CVE-2017-1292

Disclosure Date: May 26, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.
0