IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
Control Desk
Subscribe
Maximo Asset Configuration Manager
Subscribe
Maximo Asset Health Insights
Subscribe
Maximo Asset Management
Subscribe
Maximo Asset Management Scheduler
Subscribe
Maximo Asset Management Scheduler Plus
Subscribe
Maximo Calibration
Subscribe
Maximo Enterprise Adapter
Subscribe
Maximo Equipment Maintenance Assistant
Subscribe
Maximo For Aviation
Subscribe
Maximo For Life Sciences
Subscribe
Maximo For Nuclear Power
Subscribe
Maximo For Oil And Gas
Subscribe
Maximo For Service Providers
Subscribe
Maximo For Transportation
Subscribe
Maximo For Utilities
Subscribe
Maximo Linear Asset Manager
Subscribe
Maximo Network On Blockchain
Subscribe
Maximo Spatial Asset Management
Subscribe
Tivoli Integration Composer
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-25656 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T17:59:43.403Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4409
No data.
Status : Modified
Published: 2020-09-16T16:15:15.030
Modified: 2024-11-21T05:32:42.300
Link: CVE-2020-4409
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD