CVE-2020-4409: High severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.
Other sources
IBM Maximo Asset Management could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-4409.
What is the severity level of CVE-2020-4409?
The severity level of CVE-2020-4409 is high.
Which software products are affected by CVE-2020-4409?
IBM Maximo Asset Management versions 7.6.0 and 7.6.1, as well as IBM Control Desk, IBM Maximo Asset Configuration Manager, IBM Maximo Asset Health Insights, and others are affected.
How can a remote attacker exploit CVE-2020-4409?
A remote attacker can exploit CVE-2020-4409 by conducting phishing attacks using a tabnabbing technique.
Where can I find more information about CVE-2020-4409?
You can find more information about CVE-2020-4409 on the IBM X-Force Exchange website and the IBM Support website.