3 results (0.004 seconds)

CVSS: 6.2EPSS: 0%CPEs: 2EXPL: 0

28 Nov 2022 — IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 237407. IBM Maximo Mobile 8.7 y 8.8 almacena las credenciales de usuario en texto plano que puede ser leído por un usuario local. ID de IBM X-Force: 237407. • https://exchange.xforce.ibmcloud.com/vulnerabilities/237407 • CWE-256: Plaintext Storage of a Password CWE-522: Insufficiently Protected Credentials •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

14 Sep 2022 — IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163. IBM Maximo Asset Management versiones 7.6.1.1 y 7.6.1.2, podría permitir a un atacante remoto obtener información confidencial cuando es devuelto un mensaje de error técnico detallado en el navegador. Esta información podría usarse en otros... • https://exchange.xforce.ibmcloud.com/vulnerabilities/210163 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 7.2EPSS: 0%CPEs: 3EXPL: 0

03 May 2022 — IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 205680. IBM Maximo Asset Management versiones 7.6.1.1 y 7.6.1.2, e... • https://exchange.xforce.ibmcloud.com/vulnerabilities/205680 • CWE-116: Improper Encoding or Escaping of Output •