CVE-2019-4478
- EPSS 0.19%
- Veröffentlicht 12.05.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:43:39
IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information that they should not normally have access to. IBM X-Force ID: 163998.
CVE-2019-4446
- EPSS 0.12%
- Veröffentlicht 17.04.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:43:37
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
CVE-2019-4644
- EPSS 0.17%
- Veröffentlicht 17.04.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:43:54
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2019-4749
- EPSS 0.16%
- Veröffentlicht 17.04.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:44:06
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2019-4745
- EPSS 0.18%
- Veröffentlicht 24.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:05
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
CVE-2019-4583
- EPSS 0.22%
- Veröffentlicht 20.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:43:46
IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 167289.
CVE-2013-3323
- EPSS 0.53%
- Veröffentlicht 18.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:53:23
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthori...
CVE-2019-4530
- EPSS 0.22%
- Veröffentlicht 20.11.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:41
IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.
CVE-2019-4486
- EPSS 0.21%
- Veröffentlicht 24.10.2019 12:15:12
- Zuletzt bearbeitet 21.11.2024 04:43:39
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2019-4512
- EPSS 0.12%
- Veröffentlicht 09.10.2019 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:43:40
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.