CVE-2021-38935: High severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
Other sources
IBM Maximo Asset Management does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38935.
What is the severity of CVE-2021-38935?
CVE-2021-38935 has a severity rating of 7.5, which is considered high.
Which version of IBM Maximo Asset Management is affected by this vulnerability?
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.1 are affected by this vulnerability.
Does IBM Maximo Asset Management require strong passwords by default?
No, IBM Maximo Asset Management 7.6.1.2 does not require strong passwords by default.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability to compromise user accounts in IBM Maximo Asset Management.