5.5

CVE-2019-4446

IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.

Data is provided by the National Vulnerability Database (NVD)
IbmControl Desk Version7.6.1
IbmControl Desk Version7.6.1.1
IbmMaximo Asset Health Insights Version7.6.1.1
IbmMaximo Asset Management Version7.6.0
IbmMaximo Asset Management Version7.6.1
IbmMaximo Asset Management Version7.6.1.1
IbmMaximo Calibration Version7.6
IbmMaximo Enterprise Adapter Version7.6.1
IbmMaximo For Aviation Version7.6.6
IbmMaximo For Aviation Version7.6.7
IbmMaximo For Aviation Version7.6.8
IbmMaximo For Life Sciences Version7.6
IbmMaximo For Nuclear Power Version7.6.1
IbmMaximo For Oil And Gas Version7.6.1
IbmMaximo For Service Providers Version7.6.3.1
IbmMaximo For Service Providers Version7.6.3.2
IbmMaximo For Service Providers Version7.6.3.3
IbmMaximo For Transportation Version7.6.2.3
IbmMaximo For Transportation Version7.6.2.4
IbmMaximo For Transportation Version7.6.2.5
IbmMaximo For Utilities Version7.6.0.1
IbmMaximo For Utilities Version7.6.0.2
IbmMaximo Linear Asset Manager Version7.6.0.1
IbmMaximo Linear Asset Manager Version7.6.0.2
IbmMaximo Linear Asset Manager Version7.6.0.3
IbmMaximo Network On Blockchain Version7.6.0.0
IbmMaximo Network On Blockchain Version7.6.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.271
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
psirt@us.ibm.com 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N