Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Maximo Asset Management
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20509 1 Ibm 1 Maximo Asset Management 2021-08-20 10.0 HIGH 9.8 CRITICAL
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.
CVE-2020-4493 1 Ibm 1 Maximo Asset Management 2021-07-21 7.5 HIGH 9.8 CRITICAL
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995.
CVE-2013-3323 1 Ibm 13 Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials and 10 more 2020-02-21 6.8 MEDIUM 9.8 CRITICAL
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
CVE-2017-1175 1 Ibm 1 Maximo Asset Management 2017-07-18 7.5 HIGH 9.8 CRITICAL
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.