CVE-2019-4591: High severity ibm maximo asset management vulnerability
Published Jul 8, 2020
·Updated
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
Other sources
IBM Maximo Asset Management does not invalidate session after logout which could allow a local user to impersonate another user on the system.
Affected Software
4 affected components
IBM Maximo Asset Management<=7.6.0
IBM Maximo Asset Management<=7.6.1
IBM Maximo Asset Management>=7.6.0.0<7.6.0.10
IBM Maximo Asset Management>=7.6.1.0<7.6.1.1
Remediation
Patch Available
Event History
Jul 8, 2020
CVE Published
via IBM·12:00 AM
Jul 13, 2020
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-4591.
2
What is the severity of CVE-2019-4591?
The severity of CVE-2019-4591 is high with a severity value of 7.8.
3
Which version of IBM Maximo Asset Management is affected by CVE-2019-4591?
IBM Maximo Asset Management versions 7.6.0 and 7.6.1 are affected by CVE-2019-4591.
4
What is the impact of CVE-2019-4591?
CVE-2019-4591 allows a local user to impersonate another user on the system.
5
Is there a fix available for CVE-2019-4591?
Please refer to IBM's support page for instructions on how to fix CVE-2019-4591.