Skip to main content

Vendor/product archive

ibm / maximo_asset_management CVEs

Beta · best-effort

182 CVEs tagged to ibm / maximo_asset_management4 Critical, 19 High, 130 Medium, 29 Low, 0 Unrated.

CVE-2025-2986

Published Apr 25, 2025

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2987

Published Apr 22, 2025

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, po…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45077

Published Jan 24, 2025

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45652

Published Jan 19, 2025

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot"…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45088

Published Nov 11, 2024

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32333

Published Feb 2, 2024

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43866

Published May 5, 2023

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27864

Published Apr 28, 2023

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the vi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27860

Published Apr 27, 2023

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. I…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40616

Published Sep 21, 2022

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tasks they should not have access…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35714

Published Aug 26, 2022

IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intende…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22436

Published Apr 21, 2022

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22435

Published Apr 21, 2022

IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38935

Published Feb 18, 2022

IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 182 CVEsPage 1 of 8