Directory Traversal Vulnerability in IBM Maximo MXAPIASSET API
CVE-2024-45652

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 January 2025

What is CVE-2024-45652?

The IBM Maximo MXAPIASSET API version 7.6.1.3 is susceptible to directory traversal, enabling remote attackers to exploit the system by crafting malicious URL requests. By utilizing 'dot dot' sequences (/../), an attacker may gain access to arbitrary files on the server. This vulnerability poses a significant risk as it could allow unauthorized users to read sensitive data, thus compromising the integrity and confidentiality of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Maximo Asset Management 7.6.1.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.