First published: Tue Sep 01 2020(Updated: )
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | <=7.6.0 | |
IBM Maximo Asset Management | <=7.6.1 | |
IBM Maximo Asset Management | >=7.6.0.0<7.6.0.10 | |
IBM Maximo Asset Management | >=7.6.1.0<7.6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4493.
The severity of CVE-2020-4493 is critical.
IBM Maximo Asset Management versions 7.6.0 and 7.6.1 are affected by CVE-2020-4493.
An attacker can bypass authentication and issue commands using a specially crafted HTTP command.
You can find more information about CVE-2020-4493 at the following references: [IBM X-Force ID: 181995](https://exchange.xforce.ibmcloud.com/vulnerabilities/181995) and [IBM Support page](https://www.ibm.com/support/pages/node/6340281).