CVE-2021-20509: Critical severity IBM Maximo Asset Management vulnerability
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.
Other sources
IBM Maximo Asset Management is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20509.
What is the severity of CVE-2021-20509?
CVE-2021-20509 has a severity rating of 9.8 (Critical).
What is CSV Injection?
CSV Injection is a type of vulnerability where an attacker can manipulate a CSV file to inject malicious content that can be executed by the application.
How does CVE-2021-20509 affect IBM Maximo Asset Management?
CVE-2021-20509 can potentially allow a remote attacker to execute arbitrary commands on the system due to improper validation of CSV file contents in IBM Maximo Asset Management version 7.6.0 and 7.6.1.
How can I fix the vulnerability in IBM Maximo Asset Management?
To fix the vulnerability in IBM Maximo Asset Management, it is recommended to apply the necessary patches or updates provided by IBM.