Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2019-4429

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162886.
Attacker Value
Unknown

CVE-2019-4486

Disclosure Date: October 24, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
Attacker Value
Unknown

CVE-2019-4512

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
Attacker Value
Unknown

CVE-2019-4364

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
Attacker Value
Unknown

CVE-2019-4303

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.
Attacker Value
Unknown

CVE-2019-4048

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.
Attacker Value
Unknown

CVE-2018-2028

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.
Attacker Value
Unknown

CVE-2019-4056

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
Attacker Value
Unknown

CVE-2018-1528

Disclosure Date: August 06, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
0
Attacker Value
Unknown

CVE-2018-1524

Disclosure Date: August 03, 2018 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
0