CVE-2022-22435
https://notcve.org/view.php?id=CVE-2022-22435
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Maximo Asset Management versión 7.6.1.2, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista y conllevando potencialmente a una divulgación de credenciales en una sesión confiable • https://exchange.xforce.ibmcloud.com/vulnerabilities/224162 https://www.ibm.com/support/pages/node/6573669 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-38935
https://notcve.org/view.php?id=CVE-2021-38935
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892. IBM Maximo Asset Management versión 7.6.1.2, no requiere que usuarios tengan contraseñas seguras por defecto, lo que facilita a atacantes comprometer las cuentas de usuarios. IBM X-Force ID: 210892 • https://exchange.xforce.ibmcloud.com/vulnerabilities/210892 https://www.ibm.com/support/pages/node/6557318 • CWE-521: Weak Password Requirements •
CVE-2021-29743
https://notcve.org/view.php?id=CVE-2021-29743
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando así la funcionalidad prevista, conllevando potencialmente a una divulgación de credenciales en una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/201693 https://www.ibm.com/support/pages/node/6484679 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-29744
https://notcve.org/view.php?id=CVE-2021-29744
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, conllevando potencialmente a una divulgación de credenciales en una sesión confiable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/201694 https://www.ibm.com/support/pages/node/6484391 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-20509
https://notcve.org/view.php?id=CVE-2021-20509
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es potencialmente vulnerable a una inyección CSV. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, causados por la comprobación inapropiada del contenido de los archivos csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/198243 https://www.ibm.com/support/pages/node/6480377 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •