Page 2 of 58 results (0.004 seconds)

CVSS: 6.0EPSS: 0%CPEs: 2EXPL: 0

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado inyecte comandos en órdenes de trabajo que podrían ser ejecutadas por otro usuario que descargue el archivo afectado. IBM X-Force ID: 126538. • http://www.ibm.com/support/docview.wss?uid=swg22006650 http://www.securityfocus.com/bid/100697 https://exchange.xforce.ibmcloud.com/vulnerabilities/126538 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 4.3EPSS: 0%CPEs: 38EXPL: 0

IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado manipulase órdenes de trabajo para falsificar correos electrónicos. Esto podría emplearse para llevar a cabo ataques más avanzados. IBM X-Force ID: 126684. • http://www.ibm.com/support/docview.wss?uid=swg22006647 http://www.securityfocus.com/bid/100214 https://exchange.xforce.ibmcloud.com/vulnerabilities/126684 • CWE-20: Improper Input Validation •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a la inyección de sentencias SQL. Un atacante remoto podría enviar sentencias SQL especialmente modificadas, lo que permitiría al atacante ver, añadir modificar o borrar información en el back-end de la base de datos. • http://www.ibm.com/support/docview.wss?uid=swg22005212 http://www.securityfocus.com/bid/99363 https://exchange.xforce.ibmcloud.com/vulnerabilities/123297 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a lo usuarios incrustar código Javascript aleatorio en la interfaz web lo que alteraría la funcionalidad planeada potencialmente llevando a la revelación de las credenciales dentro de una sesión confiable. • http://www.ibm.com/support/docview.wss?uid=swg22005243 http://www.securityfocus.com/bid/99367 https://exchange.xforce.ibmcloud.com/vulnerabilities/123778 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.3EPSS: 0%CPEs: 4EXPL: 0

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 http://www.securityfocus.com/bid/99371 https://exchange.xforce.ibmcloud.com/vulnerabilities/123299 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •