8.2

CVE-2020-4409

IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.

Data is provided by the National Vulnerability Database (NVD)
IbmControl Desk Version7.6.1
IbmControl Desk Version7.6.1.1
IbmMaximo Asset Health Insights Version7.6.1.1
IbmMaximo Asset Management Version < 7.6.1.2
IbmMaximo Calibration Version7.6
IbmMaximo Enterprise Adapter Version7.6.1
IbmMaximo For Aviation Version7.6.6
IbmMaximo For Aviation Version7.6.7
IbmMaximo For Aviation Version7.6.8
IbmMaximo For Life Sciences Version7.6
IbmMaximo For Nuclear Power Version7.6.1
IbmMaximo For Oil And Gas Version7.6.1
IbmMaximo For Service Providers Version7.6.3.1
IbmMaximo For Service Providers Version7.6.3.2
IbmMaximo For Service Providers Version7.6.3.3
IbmMaximo For Transportation Version7.6.2.3
IbmMaximo For Transportation Version7.6.2.4
IbmMaximo For Transportation Version7.6.2.5
IbmMaximo For Utilities Version7.6.0.1
IbmMaximo For Utilities Version7.6.0.2
IbmMaximo Linear Asset Manager Version7.6.0
IbmMaximo Linear Asset Manager Version7.6.0.2
IbmMaximo Linear Asset Manager Version7.6.0.3
IbmMaximo Network On Blockchain Version7.6.0.0
IbmMaximo Network On Blockchain Version7.6.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.337
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
psirt@us.ibm.com 6.8 2.3 4
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.