First published: Tue Oct 08 2019(Updated: )
IBM Maximo Asset Management generates an error message that includes sensitive information that could be used in further attacks against the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | =7.6.1.1 | |
IBM Control Desk | =7.6.0 | |
IBM Control Desk | =7.6.0.1 | |
Ibm Maximo For Aviation | =7.6 | |
Ibm Maximo For Aviation | =7.6.1 | |
Ibm Maximo For Aviation | =7.6.2 | |
Ibm Maximo For Aviation | =7.6.2.1 | |
Ibm Maximo For Aviation | =7.6.3 | |
Ibm Maximo For Life Sciences | =7.6 | |
Ibm Maximo For Nuclear Power | =7.6.0 | |
Ibm Maximo For Oil And Gas | =7.6.0 | |
Ibm Maximo For Transportation | =7.6.1 | |
Ibm Maximo For Transportation | =7.6.2 | |
Ibm Maximo For Transportation | =7.6.2.1 | |
Ibm Maximo For Transportation | =7.6.2.2 | |
Ibm Maximo For Transportation | =7.6.2.3 | |
Ibm Maximo For Transportation | =7.6.2.4 | |
Ibm Maximo For Utilities | =7.6 | |
IBM SmartCloud Control Desk | ||
IBM Maximo Asset Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-4512.
The severity of CVE-2019-4512 is medium, with a severity value of 4.3.
IBM Maximo Asset Management versions 7.6.1.1, IBM Control Desk version 7.6.0 and 7.6.0.1, IBM Maximo For Aviation versions 7.6, 7.6.1, 7.6.2, 7.6.2.1, and 7.6.3, IBM Maximo For Life Sciences version 7.6, IBM Maximo For Nuclear Power version 7.6.0, IBM Maximo For Oil And Gas version 7.6.0, and IBM Maximo For Transportation versions 7.6.1, 7.6.2, 7.6.2.1, 7.6.2.2, 7.6.2.3, and 7.6.2.4 are affected by CVE-2019-4512.
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information.
The IBM X-Force ID associated with this vulnerability is 164554.
You can find more information about CVE-2019-4512 on the IBM X-Force Exchange website or the IBM support pages.