CVE-2017-1208
https://notcve.org/view.php?id=CVE-2017-1208
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a lo usuarios incrustar código Javascript aleatorio en la interfaz web lo que alteraría la funcionalidad planeada potencialmente llevando a la revelación de las credenciales dentro de una sesión confiable. • http://www.ibm.com/support/docview.wss?uid=swg22005243 http://www.securityfocus.com/bid/99367 https://exchange.xforce.ibmcloud.com/vulnerabilities/123778 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-1176
https://notcve.org/view.php?id=CVE-2017-1176
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 http://www.securityfocus.com/bid/99371 https://exchange.xforce.ibmcloud.com/vulnerabilities/123299 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9984
https://notcve.org/view.php?id=CVE-2016-9984
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276. Maximo Asset Management versiones 7.5 y 7.6 de IBM, podría permitir a un atacante identificado remoto ejecutar comandos arbitrarios en el sistema como administrador. ID de IBM X-Force: 120276. • http://www.ibm.com/support/docview.wss?uid=swg21998608 https://exchange.xforce.ibmcloud.com/vulnerabilities/120276 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-8987
https://notcve.org/view.php?id=CVE-2016-8987
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un usuario autenticado visualizar un conjunto de elementos inapropiados que no deberían tener acceso para visualización. • http://www.ibm.com/support/docview.wss?uid=swg21996255 http://www.securityfocus.com/bid/97369 https://exchange.xforce.ibmcloud.com/vulnerabilities/119039 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-9977
https://notcve.org/view.php?id=CVE-2016-9977
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un atacante remoto secuestrar la sesión de usuario, causado por un fallo para invalidar un identificador de sesión existente. Un atacante podría explotar esta vulnerabilidad para conseguir acceso a la sesión de otro usuario. • http://www.ibm.com/support/docview.wss?uid=swg22003981 http://www.securityfocus.com/bid/98786 https://exchange.xforce.ibmcloud.com/vulnerabilities/120253 • CWE-20: Improper Input Validation •