PT-2020-10952 · Ibm · Ibm Maximo Asset Management

Published

2020-04-17

·

Updated

2021-07-21

·

CVE-2019-4446

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Maximo Asset Management version 7.6
Description The issue allows an authenticated user to perform actions they are not authorized to by modifying request parameters.
Recommendations For IBM Maximo Asset Management version 7.6, consider restricting access to sensitive features and parameters until a patch is available. As a temporary workaround, monitor and limit modifications to request parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-4446

Affected Products

Ibm Maximo Asset Management