Vulnerability CVE-2020-4529


Published: 2020-06-08

Description:
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 182713.

Type:

CWE-918

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Maximo asset management 

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/182713
https://www.ibm.com/support/pages/node/6220528

Copyright 2024, cxsecurity.com

 

Back to Top