CVE-2021-38924
- EPSS 0.91%
- Veröffentlicht 14.09.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:18:13
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IB...
CVE-2021-29854
- EPSS 1.1%
- Veröffentlicht 03.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:55
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inj...
CVE-2021-29743
- EPSS 0.5%
- Veröffentlicht 30.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:43
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis...
CVE-2021-29744
- EPSS 0.5%
- Veröffentlicht 27.08.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:43
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure...