Skip to main content

Vendor/product archive

ibm / control_desk CVEs

Beta · best-effort

15 CVEs tagged to ibm / control_desk0 Critical, 2 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2022-22330

Published Sep 13, 2022

IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22329

Published Sep 13, 2022

IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20559

Published May 10, 2021

IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inte…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4429

Published Feb 19, 2020

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 5.4 · Medium

CVE-2019-4512

Published Oct 9, 2019

IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.

CVSS 4.3 · Medium

CVE-2019-4364

Published Jun 19, 2019

IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 16168…

CVSS 8.0 · High

CVE-2019-4303

Published Jun 19, 2019

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium

CVE-2019-4056

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.

CVSS 4.3 · Medium

CVE-2019-4048

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.

CVSS 2.1 · Low

CVE-2018-2028

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive informa…

CVSS 6.5 · Medium
Showing 1-15 of 15 CVEsPage 1 of 1