First published: Wed Jun 19 2019(Updated: )
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.6 | |
IBM Control Desk | =7.6.0 | |
IBM Control Desk | =7.6.0.1 | |
Ibm Maximo For Aviation | =7.6 | |
Ibm Maximo For Aviation | =7.6.1 | |
Ibm Maximo For Aviation | =7.6.2 | |
Ibm Maximo For Aviation | =7.6.2.1 | |
Ibm Maximo For Aviation | =7.6.3 | |
Ibm Maximo For Life Sciences | =7.6 | |
Ibm Maximo For Nuclear Power | =7.6.0 | |
Ibm Maximo For Oil And Gas | =7.6.0 | |
Ibm Maximo For Transportation | =7.6.1 | |
Ibm Maximo For Transportation | =7.6.2 | |
Ibm Maximo For Transportation | =7.6.2.1 | |
Ibm Maximo For Transportation | =7.6.2.2 | |
Ibm Maximo For Transportation | =7.6.2.3 | |
Ibm Maximo For Transportation | =7.6.2.4 | |
Ibm Maximo For Utilities | =7.6 | |
IBM SmartCloud Control Desk | ||
IBM Maximo Asset Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-4364.
The severity level of vulnerability CVE-2019-4364 is high with a severity value of 8.
Vulnerability CVE-2019-4364 affects IBM Maximo Asset Management version 7.6.
A remote authenticated attacker can exploit vulnerability CVE-2019-4364 by performing CSV injection and executing arbitrary commands on the system.
Yes, there are references available for vulnerability CVE-2019-4364. You can find them at the following links: [link1](http://www.securityfocus.com/bid/108910), [link2](https://exchange.xforce.ibmcloud.com/vulnerabilities/161680), [link3](https://www.ibm.com/support/docview.wss?uid=ibm10887557).