PT-2020-10952 · Ibm · Ibm Maximo Asset Management
Published
2020-04-17
·
Updated
2021-07-21
·
CVE-2019-4446
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Maximo Asset Management version 7.6
Description
The issue allows an authenticated user to perform actions they are not authorized to by modifying request parameters.
Recommendations
For IBM Maximo Asset Management version 7.6, consider restricting access to sensitive features and parameters until a patch is available. As a temporary workaround, monitor and limit modifications to request parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Maximo Asset Management