First published: Fri Nov 06 2020(Updated: )
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 186023.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Maximo Spatial Asset Management | =7.6.0.3 | |
IBM Maximo Spatial Asset Management | =7.6.0.4 | |
IBM Maximo Spatial Asset Management | =7.6.0.5 | |
IBM Maximo Spatial Asset Management | =7.6.1.0 | |
<=7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4650 is medium.
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 allows web pages to be stored locally by default.
Another user on the system can read the locally stored web pages in IBM Maximo Spatial Asset Management due to a vulnerability in the system.
Yes, IBM has released patches to address the vulnerability in IBM Maximo Spatial Asset Management.
You can find more information about CVE-2020-4650 on the IBM X-Force Exchange website and the IBM support page.