Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2020-4651

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024.
Attacker Value
Unknown

CVE-2020-4650

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
Attacker Value
Unknown

CVE-2020-4529

Disclosure Date: June 05, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
Attacker Value
Unknown

CVE-2019-4745

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
Attacker Value
Unknown

CVE-2018-1528

Disclosure Date: August 06, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
0
Attacker Value
Unknown

CVE-2018-1524

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
0