CVE-2021-38924: High severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 210163.
Other sources
IBM Maximo Asset Management could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38924.
What is the severity of CVE-2021-38924?
The severity of CVE-2021-38924 is high with a severity value of 7.5.
Which software versions are affected by CVE-2021-38924?
IBM Maximo Asset Management versions 7.6.1.1 and 7.6.1.2 are affected by CVE-2021-38924.
How can a remote attacker exploit CVE-2021-38924?
A remote attacker can exploit CVE-2021-38924 by obtaining sensitive information through a detailed technical error message returned in the browser.
Are there any references related to CVE-2021-38924?
Yes, you can find more information about CVE-2021-38924 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/210163) and [Reference 2](https://www.ibm.com/support/pages/node/6620059).