Page 2 of 96 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548. IBM Maximo Asset Management en sus versiones 7.5 y 7.6 podría permitir que un atacante remoto lleve a cabo ataques de phishing empleando un ataque de redirección abierta. • http://www.ibm.com/support/docview.wss?uid=swg22010595 http://www.securityfocus.com/bid/102211 https://exchange.xforce.ibmcloud.com/vulnerabilities/131548 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.0EPSS: 0%CPEs: 2EXPL: 0

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado inyecte comandos en órdenes de trabajo que podrían ser ejecutadas por otro usuario que descargue el archivo afectado. IBM X-Force ID: 126538. • http://www.ibm.com/support/docview.wss?uid=swg22006650 http://www.securityfocus.com/bid/100697 https://exchange.xforce.ibmcloud.com/vulnerabilities/126538 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 4.3EPSS: 0%CPEs: 38EXPL: 0

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado manipulase órdenes de trabajo para falsificar correos electrónicos. Esto podría emplearse para llevar a cabo ataques más avanzados. IBM X-Force ID: 126684. • http://www.ibm.com/support/docview.wss?uid=swg22006647 http://www.securityfocus.com/bid/100214 https://exchange.xforce.ibmcloud.com/vulnerabilities/126684 • CWE-20: Improper Input Validation •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a lo usuarios incrustar código Javascript aleatorio en la interfaz web lo que alteraría la funcionalidad planeada potencialmente llevando a la revelación de las credenciales dentro de una sesión confiable. • http://www.ibm.com/support/docview.wss?uid=swg22005243 http://www.securityfocus.com/bid/99367 https://exchange.xforce.ibmcloud.com/vulnerabilities/123778 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.3EPSS: 0%CPEs: 4EXPL: 0

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 http://www.securityfocus.com/bid/99371 https://exchange.xforce.ibmcloud.com/vulnerabilities/123299 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •