Skip to main content

Vendor/product archive

ibm / maximo_for_aviation CVEs

Beta · best-effort

19 CVEs tagged to ibm / maximo_for_aviation0 Critical, 3 High, 15 Medium, 1 Low, 0 Unrated.

CVE-2019-4429

Published Feb 19, 2020

IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 5.4 · Medium

CVE-2019-4486

Published Oct 24, 2019

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium

CVE-2019-4512

Published Oct 9, 2019

IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.

CVSS 4.3 · Medium

CVE-2019-4364

Published Jun 19, 2019

IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 16168…

CVSS 8.0 · High

CVE-2019-4303

Published Jun 19, 2019

IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium

CVE-2019-4056

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.

CVSS 4.3 · Medium

CVE-2019-4048

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.

CVSS 2.1 · Low

CVE-2018-2028

Published Jun 6, 2019

IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive informa…

CVSS 6.5 · Medium

CVE-2018-1524

Published Aug 3, 2018

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulne…

CVSS 8.8 · High

CVE-2016-5902

Published Feb 8, 2017

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func…

CVSS 6.1 · Medium
Showing 1-19 of 19 CVEsPage 1 of 1