Cross-Site Request Forgery Vulnerability in IBM Maximo Spatial Asset Management
CVE-2020-4651

4.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
9 November 2020

Summary

IBM Maximo Spatial Asset Management versions 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 are susceptible to a cross-site request forgery vulnerability. This flaw may enable attackers to execute unauthorized actions on the behalf of authenticated users without their consent, leveraging the trust established between the user and the website. This can have serious implications for organizational security, allowing potential manipulation of trusted transactions.

Affected Version(s)

Maximo Spatial Asset Management 7.6.0.3

Maximo Spatial Asset Management 7.6.0.4

Maximo Spatial Asset Management 7.6.0.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.