90 results (0.005 seconds)

CVSS: 8.2EPSS: 0%CPEs: 42EXPL: 0

16 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/179537 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 9.8EPSS: 0%CPEs: 40EXPL: 0

18 Feb 2020 — A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access. Se presenta una vulnerabilidad de escalada de privilegios en IBM Maximo Asset Management versiones 7.5, 7.1 y 6.2, cuando WebSeal con Autenticación Básica es usado, debido a un fallo al invalidar la sesión de autenticación, lo que podría permitir a u... • http://www.securityfocus.com/bid/62685 • CWE-269: Improper Privilege Management •

CVSS: 4.3EPSS: 0%CPEs: 29EXPL: 0

27 Mar 2018 — IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460. IBM Maximo Asset Management 7.1, 7.5 y 7.6; Maximo Asset Management Essentials 7.1 y 7.5; Control Desk 7.5 y 7.6; Tivoli Asset Management for IT 7.1 y 7.... • http://www-01.ibm.com/support/docview.wss?uid=swg21971160 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 3.3EPSS: 0%CPEs: 4EXPL: 0

05 Jul 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

05 Jul 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a la inyección de sentencias SQL. Un atacante remoto podría enviar sentencias SQL especialmente modificadas, lo que permitiría al atacante ver, añadir modificar o borrar información en el ba... • http://www.ibm.com/support/docview.wss?uid=swg22005212 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

05 Jul 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a lo usuarios incrustar código Javascript aleatorio en la interfaz web lo que alteraría la funcional... • http://www.ibm.com/support/docview.wss?uid=swg22005243 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

08 Jun 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un usuario autenticado visualizar un conjunto de elementos inapropiados que no deberían tener acceso para visualización. • http://www.ibm.com/support/docview.wss?uid=swg21996255 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 1%CPEs: 5EXPL: 0

07 Jun 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. Maximo Asset Management versiones 7.1, 7.5 y 7.6 de IBM, podría permitir a un atacante remoto secuestrar la sesión de usuario, causado por un fallo para invalidar un identificador de sesión existente. Un atacante podría explotar ... • http://www.ibm.com/support/docview.wss?uid=swg22003981 • CWE-20: Improper Input Validation •

CVSS: 8.4EPSS: 2%CPEs: 5EXPL: 0

03 May 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252. IBM Maximo Asset Management 7.1, 7.5, y 7.6 podría permitir a un atacante remoto incluir ficheros arbitrarios. Un atacante remoto podría enviar peticiones URL especialmente diseñadas para ejecutar código abritrario en el servidor afectado.... • http://www.ibm.com/support/docview.wss?uid=swg22002018 • CWE-284: Improper Access Control •

CVSS: 5.6EPSS: 0%CPEs: 3EXPL: 0

26 Apr 2017 — IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537. IBM Maximo Asset Management 7.1, 7.5 y 7.6 podrían permitir a un atacante remoto secuestrar la sesión de un usuario debido a un error de validación del identificador de sesión. • http://www.ibm.com/support/docview.wss?uid=swg21996256 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •