Page 4 of 212 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

14 Sep 2022 — IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163. IBM Maximo Asset Management versiones 7.6.1.1 y 7.6.1.2, podría permitir a un atacante remoto obtener información confidencial cuando es devuelto un mensaje de error técnico detallado en el navegador. Esta información podría usarse en otros... • https://exchange.xforce.ibmcloud.com/vulnerabilities/210163 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

26 Aug 2022 — IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116. IBM Maximo Asset Management versión 7.6.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/231116 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.2EPSS: 0%CPEs: 3EXPL: 0

03 May 2022 — IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 205680. IBM Maximo Asset Management versiones 7.6.1.1 y 7.6.1.2, e... • https://exchange.xforce.ibmcloud.com/vulnerabilities/205680 • CWE-116: Improper Encoding or Escaping of Output •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

21 Apr 2022 — IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224164. IBM Maximo Asset Management versión 7.6.1.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/224164 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

21 Apr 2022 — IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Maximo Asset Management versión 7.6.1.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad pre... • https://exchange.xforce.ibmcloud.com/vulnerabilities/224162 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

18 Feb 2022 — IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892. IBM Maximo Asset Management versión 7.6.1.2, no requiere que usuarios tengan contraseñas seguras por defecto, lo que facilita a atacantes comprometer las cuentas de usuarios. IBM X-Force ID: 210892 • https://exchange.xforce.ibmcloud.com/vulnerabilities/210892 • CWE-521: Weak Password Requirements •

CVSS: 2.4EPSS: 0%CPEs: 1EXPL: 0

16 Feb 2022 — IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494. Las aplicaciones IBM Maximo Anywhere versión 7.6.4.0, podrían permitir la ofuscación del código fuente de la aplicación. IBM X-Force ID: 161494 • https://exchange.xforce.ibmcloud.com/vulnerabilities/161494 •

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 0

16 Feb 2022 — IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: 161493. Las aplicaciones IBM Maximo Anywhere versión 7.6.4.0, podrían revelar información confidencial a un usuario con acceso físico al dispositivo. IBM X-Force ID: 161493 • https://exchange.xforce.ibmcloud.com/vulnerabilities/161493 •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

16 Feb 2022 — IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697. IBM Maximo Anywhere versión 7.6.4.0, podría permitir a un atacante realizar ingeniería inversa en la aplicación debido a una falta de precauciones de protección binaria. IBM X-Force ID: 160697 • https://exchange.xforce.ibmcloud.com/vulnerabilities/160697 • CWE-326: Inadequate Encryption Strength •

CVSS: 6.4EPSS: 0%CPEs: 3EXPL: 0

30 Aug 2021 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la I... • https://exchange.xforce.ibmcloud.com/vulnerabilities/201693 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •