First published: Wed Jun 03 2020(Updated: )
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Asset Management | <=7.6.0 | |
IBM Maximo Asset Management | <=7.6.1 | |
IBM Maximo Asset Management | =7.6.0.0 | |
IBM Maximo Asset Management | =7.6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4529 has been classified as a moderate severity vulnerability due to its potential for unauthorized network requests.
To fix CVE-2020-4529, it is recommended to apply the latest security patch from IBM for Maximo Asset Management versions 7.6.0 and 7.6.1.
CVE-2020-4529 affects users of IBM Maximo Asset Management versions 7.6.0 and 7.6.1.
CVE-2020-4529 is classified as a server-side request forgery (SSRF) vulnerability.
Yes, CVE-2020-4529 can potentially lead to network enumeration or facilitate other attacks due to unauthorized requests.