IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
Control Desk
Subscribe
Maximo Asset Configuration Manager
Subscribe
Maximo Asset Health Insights
Subscribe
Maximo Asset Management
Subscribe
Maximo Asset Management Scheduler
Subscribe
Maximo Asset Management Scheduler Plus
Subscribe
Maximo Calibration
Subscribe
Maximo Enterprise Adapter
Subscribe
Maximo Equipment Maintenance Assistant
Subscribe
Maximo For Aviation
Subscribe
Maximo For Life Sciences
Subscribe
Maximo For Nuclear Power
Subscribe
Maximo For Oil And Gas
Subscribe
Maximo For Service Providers
Subscribe
Maximo For Transportation
Subscribe
Maximo For Utilities
Subscribe
Maximo Linear Asset Manager
Subscribe
Maximo Network On Blockchain
Subscribe
Maximo Spatial Asset Management
Subscribe
Tivoli Integration Composer
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-14356 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-17T03:22:52.642Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-4749
No data.
Status : Modified
Published: 2020-04-17T14:15:17.957
Modified: 2024-11-21T04:44:06.040
Link: CVE-2019-4749
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD