IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
2019-06-19T14:15:11.020
2024-11-21T04:43:30.613
Modified
CVSSv3.1: 8.0 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | maximo_asset_management | 7.6 | Yes |
Application | ibm | control_desk | 7.6.0 | Yes |
Application | ibm | control_desk | 7.6.0.1 | Yes |
Application | ibm | maximo_for_aviation | 7.6 | Yes |
Application | ibm | maximo_for_aviation | 7.6.1 | Yes |
Application | ibm | maximo_for_aviation | 7.6.2 | Yes |
Application | ibm | maximo_for_aviation | 7.6.2.1 | Yes |
Application | ibm | maximo_for_aviation | 7.6.3 | Yes |
Application | ibm | maximo_for_life_sciences | 7.6 | Yes |
Application | ibm | maximo_for_nuclear_power | 7.6.0 | Yes |
Application | ibm | maximo_for_oil_and_gas | 7.6.0 | Yes |
Application | ibm | maximo_for_transportation | 7.6.1 | Yes |
Application | ibm | maximo_for_transportation | 7.6.2 | Yes |
Application | ibm | maximo_for_transportation | 7.6.2.1 | Yes |
Application | ibm | maximo_for_transportation | 7.6.2.2 | Yes |
Application | ibm | maximo_for_transportation | 7.6.2.3 | Yes |
Application | ibm | maximo_for_transportation | 7.6.2.4 | Yes |
Application | ibm | maximo_for_utilities | 7.6 | Yes |
Application | ibm | smartcloud_control_desk | - | Yes |
Application | ibm | tivoli_integration_composer | - | Yes |