![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-29743
https://notcve.org/view.php?id=CVE-2021-29743
30 Aug 2021 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la I... • https://exchange.xforce.ibmcloud.com/vulnerabilities/201693 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-29744
https://notcve.org/view.php?id=CVE-2021-29744
27 Aug 2021 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201694. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la interfaz de usuario... • https://exchange.xforce.ibmcloud.com/vulnerabilities/201694 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-20509
https://notcve.org/view.php?id=CVE-2021-20509
12 Aug 2021 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es potencialmente vulnerable a una inyección CSV. Un atacante remoto podría ejecutar comandos arbitrarios en el sistema, causados por la comprobación inapropiada del contenido de los archivos csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/198243 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-20374
https://notcve.org/view.php?id=CVE-2021-20374
19 May 2021 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a ataques de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en l... • https://exchange.xforce.ibmcloud.com/vulnerabilities/195522 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-4493
https://notcve.org/view.php?id=CVE-2020-4493
05 Oct 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, podría permitir a un atacante omitir una autenticación y emitir comandos usando un comando HTTP especialmente diseñado. IBM X-Force ID: 181995 • https://exchange.xforce.ibmcloud.com/vulnerabilities/181995 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-4409
https://notcve.org/view.php?id=CVE-2020-4409
16 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/179537 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-4526
https://notcve.org/view.php?id=CVE-2020-4526
15 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 182436. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a un ataque de tipo cross-site request forgery, lo que podría permitir a un atacante ejecutar acciones maliciosas y no autorizadas transmitidas desde un usuario en el que confía el sitio web. IBM X-Force ID: ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182436 • CWE-352: Cross-Site Request Forgery (CSRF) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-4521
https://notcve.org/view.php?id=CVE-2020-4521
15 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 182396. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, podría permitir a un atacante autenticado remoto ejecutar código arbitrario en el sistema, causado por una deserialización no segura en J... • https://exchange.xforce.ibmcloud.com/vulnerabilities/182396 • CWE-502: Deserialization of Untrusted Data •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-4671
https://notcve.org/view.php?id=CVE-2019-4671
15 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, es vulnerable a una inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, que podrían permitir al atacante visualizar, agregar, modificar o eliminar informac... • https://exchange.xforce.ibmcloud.com/vulnerabilities/171437 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-4582
https://notcve.org/view.php?id=CVE-2019-4582
13 Aug 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 167288. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, podrían permitir a un atacante remoto saltar directorios en el sistema. Un atacante podría enviar una petición de URL especialmente diseñada que contenga secuencias "dot dot" (/../) para vis... • https://exchange.xforce.ibmcloud.com/vulnerabilities/167288 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •