
CVE-2020-4409
https://notcve.org/view.php?id=CVE-2020-4409
16 Sep 2020 — IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537. IBM Maximo Asset Management versiones 7.6.0 y 7.6.1, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/179537 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2013-3323
https://notcve.org/view.php?id=CVE-2013-3323
18 Feb 2020 — A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access. Se presenta una vulnerabilidad de escalada de privilegios en IBM Maximo Asset Management versiones 7.5, 7.1 y 6.2, cuando WebSeal con Autenticación Básica es usado, debido a un fallo al invalidar la sesión de autenticación, lo que podría permitir a u... • http://www.securityfocus.com/bid/62685 • CWE-269: Improper Privilege Management •

CVE-2015-5016
https://notcve.org/view.php?id=CVE-2015-5016
27 Mar 2018 — IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460. IBM Maximo Asset Management 7.1, 7.5 y 7.6; Maximo Asset Management Essentials 7.1 y 7.5; Control Desk 7.5 y 7.6; Tivoli Asset Management for IT 7.1 y 7.... • http://www-01.ibm.com/support/docview.wss?uid=swg21971160 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1414
https://notcve.org/view.php?id=CVE-2018-1414
22 Feb 2018 — IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820. IBM Maximo Asset Management en sus versiones 7.5 y 7.6 es vulnerable a inyección SQL. Un atacante remoto podría enviar instrucciones SQL especialmente manipuladas que podrían permitir que el atacante viese, añadiese, modificase o borrase información en ... • http://www.ibm.com/support/docview.wss?uid=swg22013797 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-1499
https://notcve.org/view.php?id=CVE-2017-1499
14 Feb 2018 — IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106. IBM Maximo Asset Management versiones 7.5 y 7.6 podría permitir que un atacante remoto incluya archivos arbitrarios y, como consecuencia, ejecute código en el servidor Web vulnerable. IBM X-Force ID: 129106. • http://www.ibm.com/support/docview.wss?uid=swg22012781 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2017-1558
https://notcve.org/view.php?id=CVE-2017-1558
13 Dec 2017 — IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 131548. IBM Maximo Asset Managemen... • http://www.ibm.com/support/docview.wss?uid=swg22010595 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-1352
https://notcve.org/view.php?id=CVE-2017-1352
12 Sep 2017 — IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado inyecte comandos en órdenes de trabajo que podrían ser ejecutadas por otro usuario que descargue el archivo afectado. IBM X-Force ID: 126538. • http://www.ibm.com/support/docview.wss?uid=swg22006650 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2017-1357
https://notcve.org/view.php?id=CVE-2017-1357
09 Aug 2017 — IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. IBM Maximo Asset Management 7.5 y 7.6 podría permitir que un usuario autenticado manipulase órdenes de trabajo para falsificar correos electrónicos. Esto podría emplearse para llevar a cabo ataques más avanzados. IBM X-Force ID: 126684. • http://www.ibm.com/support/docview.wss?uid=swg22006647 • CWE-20: Improper Input Validation •

CVE-2017-1176
https://notcve.org/view.php?id=CVE-2017-1176
05 Jul 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. IBM Máximo Asset Management 7.1, 7.5 y 7.6 permite a usuarios locales obtener información sensible debido a la retención inapropiada de datos de los adjuntos. IBM X-Force ID: 123299. • http://www.ibm.com/support/docview.wss?uid=swg22005210 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1175
https://notcve.org/view.php?id=CVE-2017-1175
05 Jul 2017 — IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297. IBM Máximo Asset Management 7.1, 7.5 y 7.6 es vulnerable a la inyección de sentencias SQL. Un atacante remoto podría enviar sentencias SQL especialmente modificadas, lo que permitiría al atacante ver, añadir modificar o borrar información en el ba... • http://www.ibm.com/support/docview.wss?uid=swg22005212 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •